Help needed! Please contribute your notes to help us finish this page.
Privacy and Surveillance
- International Law
- Privacy Protection in the European Union
- Privacy Protection in the United States of America
- Privacy Protection in Australia
- The Privacy Act
- The Australian Privacy Principles
- Cyber Security and Data Breaches
- Overview
- Mandatory Data Breach Requirements (Federal)
- Mandatory Notification of Data Breach Scheme (NSW)
- Major Australian Data Breaches
- Cyber Security and Data Protection
- The Cyber Security Strategy and Australian Security Legislation
- Potential 2024 reforms to the Privacy Act
- The Privacy and Other Legislation Amendment Act 2024 (Cth)
- Doxxing
- Biometrics and the Australian privacy framework
- Government Surveillance
- Privacy-enhancing technology
- Children’s online privacy and sharenting
- The Right to be Forgotten
- The SPAM Act
- The Do Not Call Register
- Privacy Protection in India
- The Digital Afterlife
- Digital Products and Consumer Rights
Video unavailable. Please help by creating a new video on Explains How Online Technologies Affect Our Privacy.
International Law
Article 12, 1948 Universal Declaration on Human Rights (UDHR)
‘No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attack.’
The UDHR was adopted in the General Assembly as Resolution 217 on 10 December 1948. Among the 58 members of United Nations, 48 voted in favour, 8 abstained. Honduras and Yemen failed to vote or abstain. The historical vote on adoption does not affect the application of the UDHR on other member states who joined the United Nations later.
The UDHR is not a treaty and therefore does not itself create legal obligations for countries. It is an expression of fundamental values which are shared by all members of the international community, and therefore has arguably become binding as part of customary international law
Article 17, International Covenant on Civil and Political Rights (ICCPR)
‘(1) No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation’
‘(2) Everyone has the right to the protection of the law against such interference or attacks’
There are a total of 174 parties to the ICCPR.
Article 16, Convention on the Rights of the Child
‘(1) No Child shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, nor to unlawful attacks on his or her honour and reputation.
‘(2) ‘The Child has the right to the protection of the law against such interference or attacks’
Under Art 1 in the Convention, child is defined as any human being below the age of 18
Article 14 International Convention on the Protection of All Migrant Workers and Members of their families
‘No Migrant worker or member of his or her family shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home, correspondence or other communication, or to unlawful attacks on his or her honour and reputation. Each migrant worker and member of his or her family shall have the right to the protection of the law against such interference or attacks’
Treaty No.108 Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data
This treaty is open for signature by member States of the Council of Europe and for accession by non-member states since 28 January 1981. There are a total of 57 accessions to it. In summary, it provides protection for individual against abuses arising out of collecting and processing of personal data, in order to secure their rights and fundamental freedoms, in particular his right to privacy. It imposes obligation for parties to the agreement to take appropriate security measure to prevent accidental or authorised access to personal data. It also enshrines data subject’s right to know with regards to his own personal data.
OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data
Although not binding, this serves as guidelines on all OECD Member countries to uphold human rights and prevent interruptions in international flow of data. It represents a consensus on basic principles that can be included in existing national legislations or serves as basis for legislations in those countries who do not have any yet.
There are 8 principles governing the protection of privacy and transborder flow of personal data. They are: collection limitation principle, data quality principle, purpose specification principle, use limitation principle, security safeguards principle, openness principle, individual participation principle and accountability principle.
Right to privacy and the internet
Right to privacy is not confined to the physical world. In its sixty-eighth session of General Assembly, the United Nations (UN) adopted Resolution 68/177 regarding the right to privacy in the digital age. It recognized the increasing global trend of Internet usage and the advancement in information and communications technologies, and emphasised that the right to privacy also includes privacy in the digital world.
While gathering of an individual’s sensitive information may be necessary for the purpose of national and public security, it must be done in compliance with the state’s obligations in international human rights laws. Therefore UN called upon on States to review their legislation and practices relating to communication surveillance and collection of personal data so as to protect individual’s right to privacy, which also includes digital communications.
Interference with privacy
Under UDHR and ICCPR, the content of the right to privacy includes the term ‘interference’. What this essentially means is that the integrity and confidentiality of correspondence should be guaranteed de jure and de facto, without any interception and without being opened or read. Any capture of communication data may potentially fall under the ‘interference’. Therefore, as suggested by the Office of UN High Commissioner for Human Rights, mass surveillance programmes adopted by many states would already be amount to ‘interfering’, and it is on the State to prove that such interception is neither arbitrary nor unlawful.
‘Unlawful’ and ‘Arbitrary’ – Qualified rights
The right to privacy under both UDHR and ICCPR is not an absolute right. It may be restricted or limited as long as it is not ‘unlawful’. This means that member states may implement laws that specifically authorize such derogation. However, member states are not unfettered. The implemented laws must not be in contravention with the provisions in the International Covenant on Civil and Political Rights, and should be ‘reasonable in particular circumstances’.
In determining the reasonableness of such limitation, references may be drawn from Siracusa Principles and case law. In short, they all emphasise the principles of legality, necessity and proportionality. Such a law has to be readily accessible and clear. It must be necessary and should be the least intrusive option to pursue the legitimate aim.
Privacy Protection in the European Union
Enshrined under Art 8(1) Charter of Fundamental Rights of the European Union and Art 16(1) Treaty of the Functioning of the European Union, data protection is recognized as a fundamental right in the European Union (EU). To facilitate the increase of trade and digital activities between Member States, the General Data Protection Regulation (GDPR) was enacted in 2016 and came into force in May 2018 to replace the previous Data Protection Directives. This creates a more comprehensive coverage of enhanced rights and protections of individual’s personal data.
General Data Protection Regulation
Legal Basis for data processing
The GDPR formalizes 6 legal basis for personal data collection under Art 6(1). This includes:
- Consent
- Performance of contract
- Compliance with legal obligations
- Protection of vital interests of data subject
- Performance for public interest
- Legitimate interests pursued by the controller or by a third party
As well as formalising these legal bases for personal data collection, the GDPR also formalises legal bases for the removal of personal data across the European Union, which includes the right to erasure.
Consent requirement
Of the 6 legal bases for data collection, consent is the most common one since it can be applied to almost every situation, unlike the other 5 where data processor is required to reach a rigorous situational threshold.
Consent is only valid only if it is freely given, specific, informed and is unambiguous. As to the practical operation of consent required, Art 29 Working Party (WP 29) has provided further clarification on its Guidelines on Consent. While WP 29 was an advisory body replaced by the European Data Protection Board (EDPB) under GDPR, since EDPB so far has not issued anything in replacement, the WP29 document continues to serve as an interpretive guideline for GDPR and EDPB under Art 94(2) GDPR since EDPB has not issued any superseding guidelines. The Guidelines analyzed the requirements under Art 4(11) GPDR, and considered what constitutes valid consent under different situations – such as imbalance of power, bundled consent, performance of a contract etc.
Situation - Bundled consent
Bundled consent refers to consent that is given via a written declaration that contains multiple data processing purposes. For example, a mobile application asks for consent to collect data for GPS localization in their service agreement, which may also contain a clause stating that the data will be transferred to 3rd parties for advertising purpose. By signing the agreement, the data subject consents to a ‘bundle’ of data processing purposes. Although not explicitly spelt out in the law itself, it entrenched in the ‘freely given’ element and therefore bundled consent is invalid under GDPR.
In order to determine whether the situation render consent not freely given, it is essential to determine the scope of the contract and whether the collection of data is necessary for the performance of the contract. For example, by denying the unnecessary data processing, the data subject will act to their detriment since he will also deny the processing of data for the enforcement of the contract. Thus, such consent is not ‘freely given’.#
Situation - Employment
A lot of data processing arises out of employment context, no matter whether it is for application for jobs, promotion, removal or monitoring systems in the workplace. Given the imbalance of power, employees are unlikely able to respond to their employer’s request for consent freely, since they are in fear of the detrimental effect for their refusal.
Consent is freely given if three is a real choice, and no risk of deception, intimidation, coercion or significant negative consequences if data subject does not consent. Given the inherent dominance of employer in the employer-employee relationship, it is very unlikely there is no pressure when the employee gives consent. Thus, consent should not be the legal basis for processing personal data in an employment context.
Nevertheless, processing of personal data may still likely to be legitimate under Art6(1)(b) if the employer can show that the processing is necessary for the performance of the employment contract.
Situation - Granularity
Granularity refers to cases where there are multiple purposes for multiple collection of personal data. For example, service application forms may incorporate both terms and conditions of provision of the data user’s services and statements relating to the use of data collected for marketing products or services.
For multiple purpose collection, Art 7(2) and Recital 32 GDPR require consent to be given distinguishably. What this essentially means is that data subject should be given the choice to accept or reject a particular purpose, rather than having to consent to a bundle of processing purposes. A lack of granularity may invalidate consent given since it is not specific, as required under Art 6(1)(a), which is closely linked to the requirement of a freely given consent.
Performance of a Contract
Performance of a contact forms a legal basis for processing personal data where it is necessary in the context of a contract or the intention to enter into a contract.
Fulfillment of Legal Obligation
This requirement does not require a specific law for each individual processing. It is sufficient if the data user can demonstrate that the processing is necessary for the performance of a task carried out in the public interest or for official authority to exercise their power.
Vital Interest of the data subject
As suggested in Recital 46, this basis should come last in line and other legal bases under Art 6 should be exhausted first.
Legitimate interest
Personal data may be disclosed if it is of the legitimate interest of data controller, provided that the interests or fundamental rights and freedoms of the data subject are not overriding. This has to take into account of the reasonable expectations of data subjects based on their relationship with the controller
Privacy Protection in the United States of America
Constitution
The right to privacy is not explicitly provided for in the United States Constitution. However, the Bill of Rights (that is, some of the first 10 amendments to the Constitution) protect against invasion of privacy by state actors. These include the First Amendment provision on the right to free assembly, the Fourth Amendment provision against unwarranted seizure or search, the Ninth Amendment provision against denial of right due to others, and the Fourteenth Amendment provision on the right to due process. These Amendments combine to broadly establish a constitutional basis for the protection against invasion of personal privacy by state agencies.
Federal legislation
There is no particular federal legal framework that holistically provides for privacy regulation or data protection in the United States. Instead, several sector-specific federal laws focusing on different types of data represent an attempt at privacy protection legislation, including:
-
The Children’s Online Privacy Protection Act 2000 recognises the inherent safety and privacy risks posed by online harm to children and thus seeks to protect information privacy for children below the age of 13. It severely restricts the type of information or data about the children organisations are allowed to gather, distribute or appropriate. Most notably, the Act expressly requires website operators to not only notify parents but also acquire ‘verifiable parental consent’ prior to ‘collecting, using, or disclosing’ any personal and private data from children.
-
The Driver’s Privacy Protection Act 1994 seeks to protect personal information collected by the Department of Motor Vehicles. The Act regulates the privacy, storage, use, and disclosure of the personal information about drivers the Department collects on its online system with a view to safeguarding against misuse and data breaches.
-
The Video Privacy Protection Act 1988 guarantees the privacy of the personal information provided by individuals on online streaming sites. It proscribes unauthorised disclosure of personal records of people using online video streaming services, stipulates certain exceptions under which such information may be disclosed, and establishes penalties for related violations.
-
Cable Communications Policy Act 1984 establishes and safeguards subscriber privacy. It stipulates the manner in which cable system operators can collect and use personal information besides prohibiting them from collecting or using such data without first obtaining the express consent of the subscribers. The Act also restricts cable systems from collecting only the data they require to effectively offer their services to their subscribers and to safeguard cable communication from unauthorised reception.
State laws
In Alaska, the Alaska Right of Privacy Amendment 1972 expressly recognises the right to privacy for the Alaskan people and sets out explicit provisions to safeguard the right and protect it from infringement.
In Montana, the Montana Constitution in Article 2, subsection 10 expressly entrenches the right of its residents to individual privacy. The provision further recognises the right to privacy as a key component in ensuring the welfare of a free society. It prohibits the infringement of this right with the exception being when compelling state interests can be demonstrated.
Other states including Florida and Washington provide for privacy protection through their respective constitutions and varied privacy legislations. For instance, the Florida Constitution in Article 1, subsection 23 stipulates every person is entitled to be left alone and their private life to be free from any form of intrusion. The instrument however provides for instances when the government can intrude into the private life of a person effectively demonstrating that the right to privacy in the state is not absolute. Similarly, the Washington Constitution seeks to protect the privacy of its residents through Article 1, subsection 7 which prohibits the state from invading homes or disturbing the private affairs of the residents without explicit legal authority. The provision safeguards the online communication and correspondences of private individuals against illegal access, searches and interception by state actors.
Case law
Across the United States, several court decisions have concerned privacy protection.
The first such court decision was rendered in the case Pavesich v. New England Life Insurance Company (1905) in which the right to privacy was recognised based on constitutional values, common law, and natural law.
The case Cohen v. Cowles Media Co. (1991) was also instrumental in establishing standards for the intrusion of seclusion and solitude which are key elements in the protection of the right to privacy. Decisions rendered by the court in the case stipulate when the intrusion of seclusion can be said to have occurred, that is, when the perpetrator deliberately invades electronically, physically or by other means the private affairs, seclusion, solitude, or private space of a person, where such intrusion is exceedingly offensive any reasonable person. The case further established the three core considerations that ought to be made to determine if an intrusion has taken place including:
- the use of fraudulent, misleading, or deceptive tactics to gain access;
- if intrusion or invitation to intrude occurred; and
- whether privacy was expected.
The court decision in the case New York Times Co. v. Sullivan (1964) established the standard on the tort of privacy on what constitutes false light. As a result, for breach of the right to privacy a non-public person is entitled to, specifically the tort of false light, to be determined as having occurred, the purported misleading or untrue impression created about them must be determined as having been a function of actual malice. The decision has been instrumental in interpreting the right to privacy due to non-public persons hence promoting the protection of not only their personal privacy but also their emotional and mental wellbeing in the event of a breach.
Privacy Protection in Australia
Constitution
Unlike the Constitutions of many other liberal democracies, the Australian Constitution does not contain a right to privacy. Australia does not have a comprehensive Bill of Rights, either as part of the Constitution or as federal legislation. The ACT and Victoria do have legislated bills of rights enforceable against the territory- and state-level public agencies.
At the international level, Australia is a signatory to the International Convention on Civil and Political Rights (ICCPR), which does protect the right to privacy, but the Convention rights are not directly enforceable in domestic Australian law. The Australian Government views the Privacy Act 1988 (Cth) as implementing the ICCPR’s right to privacy. However, this implementation does not include a strong human right to privacy which can invalidate conflicting legislation, as is the case in many other jurisdictions which recognise the right to privacy in their Constitutions or Bills of Rights.
Common Law
Various areas of law have evolved to protect aspects of an individual’s space and reputation, including copyright, defamation, trespass, nuisance and confidentiality.
Until about 100 years ago, there was no formal legal notion of privacy in common law countries. But in 1890, a seminal US article from Warren and Brandeis called for a ‘right to privacy’, conceptualised as a ‘right to be left alone’ to be established in law.
In Australia, there is speculation as to whether a right to privacy or a tort of invasion of privacy exists in common law.
An early case, Victoria Park Racing, seemed to suggest that there was no such common law right in Australia.
But in the 2000s, there was significant development of English common law on privacy, as a result of the UK Human Rights Act (1998) coming into force which gave rise to some enforceability in domestic law of European Convention on Human Rights (ECHR) rights, including privacy and free expression. In England there is no separate tort of invasion of privacy, but the courts during this period have ‘stretched’ the tort of breach of confidence to cover privacy breaches. Furthermore, in 2004, a common law tort of invasion of privacy was found to exist in New Zealand.
A more recent Australian case, Lenah Game Meats, suggested that there could be a common law tort of invasion of privacy in Australian law. The High Court did not need to rule on that specific point given the facts of the case, but refused to rule out a more ‘suitable’ future case finding the existence of a privacy tort. The High Court suggested that a more ‘suitable’ scenario would involve a natural person rather than a legal person trying to establish the privacy tort.
So far, no such case has come up to the Australian High Court but there have been various decisions in lower courts on this issue.
A statutory right to privacy
In June 2025, changes to the Privacy Act 1988 (Cth) took effect that introduced a statutory tort for serious invasions of privacy, giving individuals a formal statutory right to privacy for the first time in Australia.1 Critics had argued that the Act was no longer fit for purpose in a digital era, and was not capable of responding adequately to threats such as doxxing and large-scale data breaches. The reform was many years in the making.
Background
Until the early 2000s, Australian law proceeded on the assumption that there was no general right to privacy, an assumption usually traced to Victoria Park Racing and Recreation Grounds Co Ltd v Taylor.2 In Australian Broadcasting Corporation v Lenah Game Meats Pty Ltd, Gummow and Hayne JJ said that Victoria Park ‘does not stand in the path of the development of such a cause of action’, and Callinan J observed that the decision ‘is unlikely to apply in a case in which there has been physical interference with a plaintiff’s property’.3 Victoria Park had previously been described as an obstacle to the development of an Australian tort for invasion of privacy.4
Lenah Game Meats stopped short of formally recognising such a tort. Reviews of Australia’s privacy laws in the years that followed suggested that statutory reform would be needed to resolve the uncertainty.
In its 2008 report For Your Information: Australian Privacy Law and Practice, the Australian Law Reform Commission (ALRC) observed that Australia was trailing other jurisdictions in developing statutory torts for invasions of privacy.5 It also found that overlapping privacy laws across federal, state and territory jurisdictions made enforcement difficult, that privacy principles differed between the private and public sectors, and that definitions in the Privacy Act were not well suited to emerging technologies.6
The Australian Competition and Consumer Commission’s Digital Platforms Inquiry — Final Report (2019) considered how consumer protection and privacy are handled in a digital era, and recommended the introduction of a statutory tort for serious invasions of privacy.7 The Privacy Act Review Report (2023) reinforced the case for reform.8 Lower courts had recognised a tort of invasion of privacy in Grosse v Purvis and Doe v Australian Broadcasting Corporation,9 but appellate courts had not, and the High Court in Smethurst v Commissioner of Police acknowledged privacy issues without resolving them.10
Statutory reform
The Privacy and Other Legislation Amendment Bill 2024 (Cth) was introduced on 12 September 2024 and passed both Houses on 29 November 2024. It received Royal Assent on 10 December 2024.11
Before the reforms, the Privacy Act largely regulated APP entities and did not provide a pathway for individuals to seek redress in the courts. It focused on information privacy — the rules governing the collection and handling of personal information by organisations and agencies regulated by the Australian Privacy Principles. Where individuals believed their data had been mishandled, they were confined to complaining to the Office of the Australian Information Commissioner (OAIC), with no specific right of action in court.
To extend the right to privacy to individuals, Schedule 2 was inserted into the Privacy Act, to be read separately from the rest of the Act.12 This positions the tort as distinct from the balance of the Privacy Act, which is directed at regulating APP entities. A plaintiff must be an individual — a statutory formalisation of the reasoning in Lenah Game Meats that an invasion of privacy is not something a company can claim.13
Elements of the tort
To succeed in an action under the statutory tort for serious invasion of privacy, the plaintiff must prove that:
- the defendant invaded the plaintiff’s privacy by intruding upon the plaintiff’s seclusion, or by misusing information that relates to the plaintiff;
- a person in the position of the plaintiff would have had a reasonable expectation of privacy in all of the circumstances;
- the invasion of privacy was intentional or reckless;
- the invasion of privacy was serious; and
- the public interest in the plaintiff’s privacy outweighed any countervailing public interest.14
The plaintiff does not need to show that they suffered damage as a result of the invasion.15
Defences and competing interests
Consultation before the ALRC’s Serious Invasions of Privacy in the Digital Era report showed strong support for a statutory tort, but also opposition on the ground that it could hinder freedom of speech, the media, public health and safety, and national security.16 The ALRC’s recommendations flagged a balancing exercise against the public interest.17
That concern was carried into the legislation through a public interest balancing test. Courts are directed to weigh countervailing public interests, such as freedom of expression and the role of the media and journalism, when determining liability, so that the tort cannot be used to suppress matters of legitimate public concern.
Schedule 2 also provides defences and exemptions. The defences, in Part 2, are that the invasion of privacy was required or authorised by or under an Australian law or a court or tribunal order; that the plaintiff, or a person with lawful authority to do so, expressly or impliedly consented; that the defendant reasonably believed the invasion was necessary to prevent or lessen a serious threat to the life, health or safety of a person; that the invasion was incidental to the lawful defence of persons or property and was proportionate, necessary and reasonable; and, where the invasion involved publication, that the defendant could establish a corresponding defamation defence of absolute privilege, publication of public documents, or fair report of proceedings of public concern.18
The exemptions, in Part 3, remove whole categories of conduct from the scheme. They cover agencies and State and Territory authorities and their staff acting in good faith, law enforcement bodies and intelligence agencies (including where the invasion involves disclosure of information to such a body), journalists, and people under 18.19
The journalism exemption is the most significant of these for the media-freedom concerns described above, and goes further than the public interest balancing test. Schedule 2 does not apply to an invasion of privacy by a journalist, a journalist’s employer or a person engaging a journalist, or a person assisting a journalist, to the extent that the invasion involves the collection, preparation for publication or publication of journalistic material; nor does it apply to the publication or distribution of journalistic material prepared for publication by a journalist. A journalist is a person who works in a professional capacity as a journalist and is subject to professional standards or a code of practice, and it is immaterial whether the invasion of privacy breaches those standards or that code.20 Separately, Schedule 2 does not apply at all to an invasion of privacy by a person who is under 18 years of age.21
Proceedings are also subject to a limitation period. A plaintiff who was under 18 when the invasion occurred must commence proceedings before their 21st birthday; otherwise, proceedings must be commenced before the earlier of one year after the plaintiff became aware of the invasion and three years after it occurred. A court may allow a later commencement where it was not reasonable in the circumstances for the plaintiff to have commenced proceedings in time, but not later than six years after the invasion occurred.22
Remedies and damages
Schedule 2 empowers courts to award damages or grant other remedies where a serious invasion of privacy is proven.23 Remedies include injunctions to restrain further invasions of privacy, declarations, and damages. The court may award damages for emotional distress.24 Aggravated damages are excluded, but exemplary or punitive damages may be awarded in exceptional circumstances.25 Damages are capped: the sum of any damages awarded for non-economic loss and any exemplary or punitive damages must not exceed the greater of $478,550 and the maximum amount of damages for non-economic loss that may be awarded in defamation proceedings under an Australian law.26
In assessing damages, courts may consider whether the defendant apologised or corrected a publication, whether the plaintiff received compensation, whether reasonable steps were taken to settle the dispute, and whether the defendant engaged in unreasonable conduct during or after the invasion of privacy.27
As at the time of writing, the statutory tort has not yet been applied by an Australian court. The discussion above therefore describes the statutory scheme rather than its judicial interpretation.
Privacy Act 1988 (Cth) and the Australian Privacy Principles
Video unavailable. Please help by creating a new video on Explains the Legal Protections for Privacy in Australia.
The Privacy Act 1988 (Cth) protects information privacy - that is, it prescribes what ‘personal information’ organisations and federal government agencies can collect about Australians, how that information can be collected and how it must be stored, the circumstances in which the information can be used and disclosed, and what Australian citizens must be told about the information collected about them. Personal information includes things like name, address, phone number, occupation, and sensitive information like health information. Other, state-level information privacy legislation also exists, which usually applies to state government agencies e.g. Information Privacy Act 2009 (QLD).
Personal privacy in Australia is protected in a de facto way, through a myriad of laws that are not designed specifically to protect privacy but which may have that effect. For example, a person may be able to preserve the privacy of their home through trespass laws. Privacy of movement may be asserted against another individual who offends against stalking laws. Laws designed to protect reputation, such as defamation laws and passing off laws, may be used to protect a person’s privacy in some cases. Finally, there are laws which protect privacy in communications, such as breach of confidence laws and the Telecommunications (Interception and Access) Act 1979 (Cth). In recent years, there has been a push to ‘fill the gaps’ in Australian privacy law, moving towards a more direct and express legal framework for protecting personal privacy. The Privacy and Other Legislation Amendment Act 2024 (Cth), for example, introduced a statutory cause of action for serious invasions of privacy, which commenced on 10 June 2025 (see Potential 2024 reforms to the Privacy Act below).
The Privacy Act
Third-party explainer: Australia Privacy Act 1988 Explained: Your Quick Guide to Australia’s Privacy Landscape. This video is produced by Clym, a privacy compliance vendor. It is general commentary, not a primary or authoritative source, and should be checked against the legislation and the regulator’s guidance. For the regulator’s own account of the Act, see the Office of the Australian Information Commissioner, The Privacy Act.
The Privacy Act 1988 (Cth) contains 13 Australian Privacy Principles (APPs) in Schedule 1. These principles apply to “APP entities”.
An “APP entity” is defined in section 6 to mean a Commonwealth government agency or an organisation. Organisation, in turn, is defined in s. 6C to include individuals, but not small business operators. Small business operators are those businesses with an annual turnover of $3 million or less and which meet the other requirements set out in section 6D.
When considering the APPs, it is important to first identify whether you are dealing with personal information or sensitive information (or both). Sensitive information is defined in section 6 to cover specified categories of personal information, including health information, genetic information and biometric information.
If a person thinks that their privacy has been breached under the Act, they may complain to the Office of the Australian Information Commissioner (OAIC) under section 36. Section 40 gives the Commissioner the power to investigate the complaint, and under section 52, the Commissioner may make a determination that an APP entity has breached the privacy principles in the Act. The Commissioner may also order that the entity take steps to ensure that the breach is not repeated and to provide redress to the complainant. If an entity does not comply with the Commissioner’s declaration, then either the individual complainant or the Commissioner can apply to the Federal Court to have the declaration enforced under s.55A.
Sections 65 and 66 of the Privacy Act provide that entities must cooperate with a Commissioner’s investigation, and there are financial penalties imposed for the failure to do so.
The Australian Privacy Principles
Video unavailable. Please help by creating a new video on Explains the APPs.
APP 1 — Open and transparent management of personal information
Ensures that APP entities manage personal information in an open and transparent way. This includes having a clearly expressed and up to date APP privacy policy.
APP 2 — Anonymity and pseudonymity
Requires APP entities to give individuals the option of not identifying themselves, or of using a pseudonym. Limited exceptions apply.
APP 3 — Collection of solicited personal information
Outlines when an APP entity can collect personal information that is solicited. It applies higher standards to the collection of ‘sensitive’ information.
APP 4 — Dealing with unsolicited personal information
Outlines how APP entities must deal with unsolicited personal information.
APP 5 — Notification of the collection of personal information
Outlines when and in what circumstances an APP entity that collects personal information must notify an individual of certain matters.
APP 6 — Use or disclosure of personal information
Outlines the circumstances in which an APP entity may use or disclose personal information that it holds.
APP 7 — Direct marketing
An organisation may only use or disclose personal information for direct marketing purposes if certain conditions are met.
APP 8 — Cross-border disclosure of personal information
Outlines the steps an APP entity must take to protect personal information before it is disclosed overseas.
Video unavailable. Please help by creating a new video on APP 8.
APP 9 — Adoption, use or disclosure of government related identifiers
Outlines the limited circumstances when an organisation may adopt a government related identifier of an individual as its own identifier, or use or disclose a government related identifier of an individual.
APP 10 — Quality of personal information
An APP entity must take reasonable steps to ensure the personal information it collects is accurate, up to date and complete. An entity must also take reasonable steps to ensure the personal information it uses or discloses is accurate, up to date, complete and relevant, having regard to the purpose of the use or disclosure.
APP 11 — Security of personal information
An APP entity must take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access,modification or disclosure. An entity has obligations to destroy or de-identify personal information in certain circumstances.
APP 12 — Access to personal information
Outlines an APP entity’s obligations when an individual requests to be given access to personal information held about them by the entity. This includes a requirement to provide access unless a specific exception applies.
Video unavailable. Please help by creating a new video on APP 12.
APP 13 — Correction of personal information
Outlines an APP entity’s obligations in relation to correcting the personal information it holds about individuals.
There has been very little case law on the application of the Privacy Act and APPs. One recent exception is the Privacy Commissioner v Telstra case involving technology journalist Ben Grubb’s metadata. Unfortunately, it is unclear in the aftermath of the case whether dynamic IP addresses constitute ‘personal information’ for the purposes of Australian privacy law. (NB It would constitute ‘personal data’ in EU data protection law.)
Privacy Commissioner v Telstra Corporation Ltd28
The case arose from a request by journalist, M. Grubb, who sought access to all metadata held by Telstra Corporation Ltd related to his mobile phone. While Telstra provided some data, it refused him access to its mobile network data, including metadata. In 2013, the (former) National Privacy Principle (‘NPP’) 6.1 (now reflected in Article 13 of the APP29) ‘…gave individuals the right to access, subject to some exceptions, their own personal information held by an organisation, such as Telstra’. 30
The Privacy Commissioner argued that this metadata constituted personal information, as Telstra had the capacity to link it to Mr. Grubb’s account, making him identifiable. The Administrative Appeals Tribunal (AAT) disagreed with the Privacy Commissioner’s assessment, ruling that the mobile network data was not information ‘about’ Mr. Grubb. Instead, the Tribunal viewed it as information about how Telstra provided services to Mr. Grubb. The Tribunal emphasised that merely being able to identify an individual from the data was insufficient; the data must also be about the individual to qualify as personal information under the Privacy Act.
The Privacy Commissioner appealed the decision, arguing that the Tribunal had misinterpreted the phrase ‘about an individual’ in the definitional context of ‘personal information’. Privacy advocates welcomed the appeal, anticipating it would provide the first comprehensive judicial guidance from the Federal Court on this fundamental concept within Australia’s privacy legislation. However, the Full Federal Court dismissed the appeal.
The judgment found that telecommunications metadata did not qualify as personal information under the Privacy Act 1988 (Cth). This ruling highlighted that the classification of technical data as personal information is context-dependent and illustrated ambiguity as to what constitutes ‘personal information’ for the purposes of privacy regulation in relation to the internet.
At [3], Dowsett J, with Kenny and Edelman JJ concurring, determined that:
… [T]he definition of the term ‘personal information’ in s 6 of the Privacy Act clearly contemplates identification of information or opinion concerning the relevant applicant… In other words, personal information is information or opinion:
-
About the relevant applicant; and
-
From which his identity is apparent or could reasonably be ascertained.
Recent Developments
To assist in elucidating the scope of the word ‘about’, the Explanatory Memorandum of the Privacy Amendment (Enhancing Privacy Protection) Bill 2012 (Cth)31 outlines two steps to determine whether information is personal information under the current Privacy Act:
-
Whether there is a sufficient nexus between the information and the individual.
-
The cost, difficulty, practicality, and likelihood that the information will be linked to identify that individual.
Cyber Security and Data Breaches
Overview
Recently, there has been significant reform in the law and strategy implemented by the Australian Government to improve cyber security with the aim of minimising the number of breaches. In addition to leaking Australian’s personal information, cybercrime is having significant economic impacts with the cost on Australian businesses increasing by approximately 14% per annum.
Data breaches sit within a broader picture of cyber security activity, although the two are measured differently. The Australian Signals Directorate (ASD) does not publish a count of data breaches; it reports two separate measures in its annual cyber threat report. The first is the number of cyber security incidents to which the ASD itself responded: over 1,100 in each of 2022–23 and 2023–24, and over 1,200 in 2024–25. The second is the number of cybercrime reports made by the public through ReportCyber: nearly 94,000 in 2022–23, over 87,400 in 2023–24, and over 84,700 in 2024–25.32 Notifications of data breaches are made separately, to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
Mandatory Data Breach Requirements (Federal)
Mandatory data breach requirements were first introduced in Australia in early 2017 as an amendment to the Privacy Act 1988 (Cth). The amendments contain a notification scheme for certain types of data breaches involving unauthorised access and disclosure of personal information likely to lead to serious harm to individuals.
The requirements are binding on APP entities, credit reporting bodies, credit providers, tax file number recipients and internet service providers.
If an entity becomes aware of a data breach, it must inform the Office of the Australian Information Commissioner (OAIC) and the individuals whose data is affected when the data breach is likely to result in serious harm to the individuals involved. If directly contacting the affected individuals is not practical, the entity may publish a statement on their website and take reasonable steps to publicise the contents of the statement. If the data breach affects one or more entities, an entity is not required to complete these steps if another entity has already done so.
Mandatory Notification of Data Breach Scheme (NSW)
Inception
On 16 November 2022, the Privacy and Personal Information Protection Amendment Bill (NSW) passed both houses of NSW Parliament with agreement being reached on 28 November 2022. The Bill came into effect on 28 November 2023 with key changes including:
- The introduction of the Mandatory Notification of Data Breaches scheme (MNDB scheme). This includes notification requirements and relevant assessment being undertaken to assess the seriousness of harm suffered due to the breach occurring.
- Application of the Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act) to all NSW state-owned corporations that are not covered under the Privacy Act 1988 (Cth).
- Unifying public sector agencies by repealing s117C of the Fines Act 1996 (NSW) to ensure all are covered under the MNDB scheme.
These key changes ensure a comprehensive framework for handling data breaches exists for both private organisations and federal bodies, as well as state-owned corporations in NSW.
Types of Breaches
The Information and Privacy Commission (IPC) is the regulator within NSW for the MNDB scheme and they identify 3 areas to which public sector agencies (including NSW Police and local councils) experience data breaches:
- Human error — for example a letter or email is sent to the incorrect recipient or an employee loses their laptop in a public space.
- System failure — for example no authentication is needed for systems containing confidential information or system automates workflows and redirects them to other users.
- Malicious or criminal attack — for example malware, hacking and phishing.
The IPC publishes quarterly statistics under the MNDB scheme, together with periodic trends reports. In the scheme’s first seven months of operation (28 November 2023 to 30 June 2024), the Privacy Commissioner received 52 notifications of eligible data breaches: 34 from the NSW government sector, nine from local government and nine from universities. Human error was the dominant cause across all three sectors, and cyber incidents were involved in 25 per cent of all notifications.33
The federal scheme attracts a much larger number of notifications. For the period July to December 2023, the OAIC reported that 67 per cent of notified breaches were attributed to malicious or criminal attack; health service providers notified the most breaches (104), followed by the finance sector (49).34 For July to December 2024, the OAIC reported that 69 per cent of notified breaches resulted from malicious or criminal attack, and that health service providers remained the sector notifying the highest number of breaches.35 The most recent figures published by the OAIC cover the 2025 calendar year, in which it received 1,205 notifications — the highest annual total since the scheme commenced in 2018. Of these, 716 were attributed to malicious or criminal activity, and health service providers were again the most affected sector, accounting for 225 notifications, or 19 per cent of the total.36
3-tier Process for Determining Eligible Breaches
Not every data breach that occurs falls under the MNDB scheme, as s 59L(2) of PPIP Act provides that only eligible breaches are captured under this scheme. To determine an eligible breach, regard must be given to s 59D(1) in that:
- Information held by a public sector agency has been unlawfully accessed, disclosed or lost (either internally or externally);
- That information was/is considered personal information (s 59B); and
- The data breach would likely result in serious harm for the individual to whom the information relates (s59D(1)(a) and s59D(1)(b)(ii)).
An agency that has a suspected eligible data breach reported to it has 30 days to conduct an assessment to determine if an eligible breach occurred. This is achieved by having an assessor appointed (s 59G) and relevant factors being considered (s 59H) such as to whom the information was released and how long they have had access to it.
If an eligible breach has occurred, agencies must notify the Information Commissioner immediately (s 59M) and the individual concerned (as soon as reasonably practical (s 59N)). Penalties could be up to $40,000 if the matter is decided in the NSW Civil and Administrative Tribunal.
Responsibilities Under the NSW Scheme
Agencies that hold personal information have a legislative responsibility to protect that information in accordance with the Information Protection Principles (IPPs) in Part 2 of the PPIP Act. As such, when an eligible breach occurs, all reasonable efforts must be made to contain the breach and mitigate the harm suffered.
Agencies are required to have a Data Breach Policy that outlines how they intend to address data breaches within their organisation as well as maintain both a public and internal register of eligible data breaches that have occurred within the agency. In addition to this, there is also a legislative onus on agencies to maintain a current Privacy Management Plan that not only outlines how personal information and privacy are reflected within the relevant organisation but the processes engaged when information is inadvertently released or unlawfully disclosed.
The Information Commissioner carries various enforcement powers, including:
- Directions can be issued in regard to providing specific information or making specific recommendations when reasonable suspicion is held that an eligible breach has occurred (s 59Y).
- Investigative powers and monitoring powers can be exercised to ensure systems, policies and procedures reflect the objectives of the Act and the agencies’ requirements to uphold legislative requirements pertaining to personal information (s 59ZA).
Of particular note within the OIAC, civil penalty proceedings were instigated in November 2023 against Australian Clinical Labs Limited (ACLL) after an investigation into the privacy practices was conducted following a 2022 reported breach. Failure to conduct an expeditious assessment and notify the Commissioner are some of the allegations raised that demonstrates at the federal level there is an appetite to prosecute offences and disregard of the IPPs.
“Serious Harm” Definition
For agencies subject to the MNDB scheme, little guidance is provided in terms of a legislative interpretation of “serious harm” but rather a collection of considerations is provided that does little to ensure a consistent application of the assessment process between agencies. There is no definition of “serious harm” prescribed within the PPIP Act. Naturally, each data breach case assessed would vary in severity and heavily depend on the case-specific factors including:
- individuals involved,
- the sensitivity of the information released,
- how the information was released,
- any known history concerning the individual, and
- the person to whom the information was released to.
The framework, although unifying, still lacks an underlying prescription of any form of what harm means or how it can be applied, without relying on cases to be tried within NCAT or through complaints lodged to the IPC.
Major Australian Data Breaches
In September 2022, Optus became the target of a large cyber attack resulting in 9.8 million customer records being breached. This raised public concern about the information that telecommunication companies hold and their ability to protect this information from being exposed or exploited.
Following this, in October 2022, Medibank was the victim of a data breach where the hackers gained access to private medical records of approximately 9.7 million Australians. In response to this, the Australian Government has reformed the law surrounding cyber security to attempt to prevent these breaches from occurring again and come up with ways to minimise the impacts of data breaches.
In March 2023, the Australian personal loan and financial services provider Latitude Financial was the subject of one of Australia’s largest data breaches. Latitude reported that approximately 7.9 million Australian and New Zealand driver licence numbers and about 53,000 passport numbers had been stolen, together with a further 6.1 million records containing names, addresses, telephone numbers and dates of birth. Those records related not only to current customers but also to former customers and to people who had applied for credit, in both Australia and New Zealand.37 The figure of “more than 14 million” commonly reported in the media is the sum of these two datasets, which may overlap; it is therefore an approximation of scale rather than a count of distinct individuals. Latitude reported that around 94 per cent of the 6.1 million records had been provided before 2013, and much of the data dated from as early as 2005, which raised questions about why companies continue to hold customer records beyond the periods for which they are required to retain them.
These breaches resulted in reputational damage to these companies as well as individual concerns from the customers regarding potential identity theft and the misuse of their sensitive personal information. Many of these companies were still using outdated encryption procedures and had insufficient monitoring systems. These breaches highlighted the need for the government to act swiftly and reform the law concerning cyber security to initiate stricter regulation and enforcement of cyber security measures.
Cyber Security and Data Protection
Cyber security plays a fundamental role in protecting private information from being leaked in a data breach. Cyber attacks present a significant challenge to the sovereignty of states and personal data; these challenges being intensified due to the ongoing evolution of AI technology. The ASD has the authority to conduct cyber operations, information security and foreign communication. The Australian Cyber Security Centre forms part of the ASD and conducts threat assessments and incidence response services to cyber incidents and threats, forming a collaborative approach to cyber security in Australia.
The Cyber Security Strategy and Australian Security Legislation
The Australian Government released the 2023-2030 Australian Cyber Security Strategy on 22 November 2023 which replaced Australia’s Cyber Security Strategy 2020. The strategy consists of six shields; strong businesses and citizens, safe technology, world-class threat sharing and blocking, protected critical infrastructure, sovereign capabilities, and resilient region and global leadership.
The strategy’s aim is preventative in nature but also seeks to achieve resilience and minimise the overall impacts that data breaches can have upon individual’s information as well as larger entities. The strategy also has a strong focus on collaboration between different departments to minimise the chance of a breach occurring through appropriate communication. To coincide with the introduction of this strategy, the Australian Government also appointed its first ever Executive Cyber Council. The role of the Council is to facilitate transparent co-management on key cyber security issues.
To facilitate this strategy the Australian Government also introduced the 2023-2030 Australian Cyber Security Action Plan which provides detail about how the strategy will be implemented across different stages. The action plan consists of multiple actions related to each of the six shields under the strategy. For example, one action under the ‘strong businesses’ shield is to support small and medium businesses to strengthen their cybersecurity.
The Cyber Security Act 2024 (Cth) received Royal Assent on 29 November 2024. It implements four of the initiatives set out in the Cyber Security Strategy, and takes effect in stages rather than all at once:
- Minimum cyber security standards for smart devices (Part 2). The standards are set by rules made under the Act. The Cyber Security (Security Standards for Smart Devices) Rules 2025 (Cth), which cover consumer-grade smart devices, were registered on 4 March 2025 and take effect 12 months after registration, from 4 March 2026, to allow industry time to adjust.
- A mandatory ransomware and cyber extortion payment reporting obligation for certain businesses (Part 3). The obligation and the Cyber Security (Ransomware Payment Reporting) Rules 2025 (Cth) started on 30 May 2025. The Rules set an annual turnover threshold of $3 million and require a report within 72 hours of a payment being made.
- A limited use obligation for the National Cyber Security Coordinator (Part 4), which commenced on 30 November 2024, the day after Royal Assent.
- A Cyber Incident Review Board (Part 5). The Cyber Security (Cyber Incident Review Board) Rules 2025 (Cth) began on 30 May 2025, after which the Minister for Cyber Security appoints members to the Board.38
Security of Critical Infrastructure Act
The Security of Critical Infrastructure Act 2018 (Cth) is one of the key pieces of legislation that governs cyber security in Australia. Relevant amendments include:
- The Security Legislation Amendment (Critical Infrastructure) Act 2021 (Cth), which came into effect on 2 December 2022 and included introducing mandatory reporting of cyber incidents and the implementation of stringent security measures.
- The Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 (SLACIP Act), which:
- added a new section 3(d): “imposing enhanced cyber security obligations on relevant entities for systems of national significance in order to improve their preparedness for, and ability to respond to, cyber security incidents;”
- introduced a new risk management program requiring that a critical infrastructure risk management program is maintained by entities who hold one or more critical infrastructure assets (Part 2A);
- introduced a requirement that the Minister to notify every reporting entity for assets that are declared to be of national significance, and the Minister also has the power to privately declare systems of national significance (Part 6A).
Potential 2024 reforms to the Privacy Act
2022 Privacy Act Review Report
In 2022, the Attorney-General’s Department of the Commonwealth of Australia released its Privacy Act Review Report (2022 Report). This followed the 2019 release of the Australian Competition and Consumer Commission’s Digital Platforms Inquiry final report and a two-year review of the efficacy and appropriateness of the Privacy Act 1988 (Cth) in the modern digital age.
The vulnerability of personal information (particularly data breaches) was highlighted as a key motivation for the 2022 Report, alongside significant privacy reforms that have taken place or are taking place abroad.
Key insights
(a) Submissions to the Attorney-General’s Department sought to retain the principles basis of the Act but supplement them with further detail. To this end, the 2022 Report proposed a new ‘fair and reasonable’ test alongside more detailed rules and mechanisms, such as more detailed guidance from the Office of the Australian Information Commissioner (OAIC), specific legislated requirements and expansion of the Australian Privacy Principles (APPs). The 2022 Report also suggested amending the object of the Act to be for the protections of personal information due to the public interest in doing so.
(b) Stakeholders were unclear as to what constituted protected ‘personal information’ under the Act. The 2022 Report proposed amendments to clarify that ‘personal information’ includes both technical and inferred information which concerns a “reasonably identifiable individual”. This clarification will avoid uncertainty as to whether individual data points (such as IP addresses and cookies) are included in the definition of ‘personal information’ as was exposed in Privacy Commissioner v Telstra Corporation Limited [2017] FCAFC 4. It also proposed extending protections to de-identified ‘personal information’, as it can be re-identified.
(c) Some submissions requested that current exemptions were removed or narrowed (including journalism, political, small business and employee record exemptions). Others were vehemently against the removal of those exemptions. In a balancing exercise, the 2022 Report proposed changes to meet changes in community expectations: small business should no longer be exempt; private sector employee information should be protected; and political and journalism exemptions should be narrowed.
(d) Stakeholders expressed strong support for increased protections for personal information under the Act. Accordingly, the 2022 Report proposed:
- better quality privacy collection notices and consents;
- a new ‘fair and reasonable’ test to underscore the APPs;
- requirements for entities to undertake a Privacy Impact Assessment before beginning any activity which may have a significant impact on individual privacy;
- additional privacy protections for children;
- introduction of OAIC guidelines for what constitutes reasonable steps to destroy unneeded personal information;
- enhancements to the Notifiable Data Breach scheme so that any harm caused by a breach can be minimised quickly and effectively;
- regulation of targeted advertising (whether the person is identified or not);
- further individual rights and control over their own personal information, modelled on the General Data Protection Regulation of the European Union; and
- a new concept of ‘controllers’ and ‘processors’ in the Act.
(e) Submissions highlighted the need for effective enforcement so as to encourage compliance with the Act and for pathways for recourse where privacy invasions fall outside the scope of the Act. The 2022 Report proposed: new powers for the Information Commissioner and further civil penalties regarding public inquiries, investigations and determinations; a review of the feasibility of industry funding models for the OAIC; the introduction of a statutory tort for serious invasions of privacy, especially for privacy invasions that fall outside the purview of the Act; and reducing the regulatory burden by streamlining privacy obligations, reducing duplication, and producing a privacy law design guide to ensure future legislative harmony.
In total, the 2022 Report made 116 proposals to the Australian Government to overhaul Australia’s privacy laws to ensure they meet the demands of the modern digital age.
The proposal for a statutory tort has since been enacted. The Privacy and Other Legislation Amendment Act 2024 (Cth) inserted a new Schedule 2 into the Privacy Act 1988 (Cth), creating a statutory tort for serious invasions of privacy, which commenced on 10 June 2025. The tort is discussed in detail at A statutory right to privacy above.39
2023 Government response to the Privacy Act Review Report
In 2023, the Government released its response to the 2022 Report and ultimately made a commitment to introduce legislation to enhance protections for the personal information of Australians. Out of the 116 proposals of the 2022 Report, the Government agreed to 38 proposals, agreed in-principle to 68 proposals (subject to further stakeholder engagement), and noted 10 proposals (without agreeing or agreeing in principle to legislative change).
Most pertinently, the Government:
(a) Agreed in principle to the introduction of a new ‘fair and reasonable’ test for the handling of personal information.
(b) Agreed in principle to amendments to clarify the concept of ‘personal information’ and to the introductions of the concept of de-identification. However, the Government only noted the proposal to introduce specific protections for de-identified information.
(c) Agreed in principle that the small business exemption should be removed, with further consultation with small businesses. Whilst the Government agreed to the narrowing of the journalism exemption, it only noted the narrowing of the political exemption.
(d) Agreed in principle that non-government entities complete Privacy Impact Assessments and to the inclusion of further protections for children. The Government also agreed in principle to the regulation of direct and targeted advertising (defining both terms and fair and reasonable targeting), but whilst the unqualified right to opt-out of direct marketing was agreed in principle, that same right for targeted advertising was only noted.
(e) Agreed to new civil penalty provisions and additional powers for the Information Commissioner to conduct investigations and to conduct public inquiries and reviews. The Government also agreed in principle to further investigation into an OAIC industry funding model.
The Government Response to the ‘ambitious’ 2022 Report has been described as “cautious and measured”.40 The Government laid out its plan to prepare draft legislation for the less contentious recommendations and leave the more contentious recommendations for further stakeholder consultation and analysis prior to implementation.
In May 2024, the Attorney-General’s Department announced that the Government planned to introduce draft legislation implementing the less contentious recommendations in August 2024. The first tranche of reforms to the Privacy Act 1988 (Cth), the Privacy and Other Legislation Amendment Bill 2024 was introduced by the Government on 12 September 2024. It passed the Senate with minor changes on 29 November 2024.
The Privacy and Other Legislation Amendment Act 2024 (Cth)
The Privacy and Other Legislation Amendment Bill 2024 (Cth) passed both Houses of Parliament on 29 November 2024 and received Royal Assent on 10 December 2024.41 The Act makes the first substantial changes to the Australian privacy regime in some years. Its key changes include:
- a statutory tort for serious invasions of privacy (see A statutory right to privacy above);
- new criminal offences directed at doxxing;
- a disclosure requirement for automated decision-making;
- a requirement that the OAIC develop a Children’s Online Privacy Code;
- ministerial power to prescribe countries that provide comparable privacy protections;
- new OAIC powers to issue infringement and compliance notices; and
- an express requirement that ‘reasonable steps’ to protect the security of personal information include technical and organisational measures.42
Doxxing
Unlike the statutory tort, doxxing was not among the 116 proposals in the Privacy Act Review Report. The Commonwealth Government moved to criminalise doxxing after the February 2024 publication of the contents of a private messaging group of more than 600 members of the Australian Jewish community. Names, professions, photographs and social media profiles were exposed, and those affected reported harassment and threats.43 The Government conducted a public consultation in March 2024, and in September 2024 doxxing offences were included in the Bill.
What is doxxing?
Doxxing — sometimes spelled ‘doxing’, and derived from ‘dropping documents’ — refers to publishing a person’s personal data online, usually with malicious intent. The eSafety Commissioner’s position statement identifies three main forms:44
- de-anonymising doxxing: revealing the identity of a previously anonymous person;
- targeting doxxing: revealing specific information that allows a person to be contacted, located or impersonated; and
- de-legitimising doxxing: revealing sensitive or intimate information about a person, such as medical, financial or legal records.
Ashley Madison (2015)
The dating website Ashley Madison was hacked by a group calling itself ‘Impact Team’. The attackers threatened to release user data unless the site shut down; when it did not, the personal details of millions of users were published online.45 The incident is an early large-scale illustration of the harms that follow the mass publication of identifying information.
The position before 2024
Australia (Commonwealth, and State and Territory). Before 2024 there was no standalone doxxing offence. A patchwork of existing laws could apply, including:
- using a carriage service to menace, harass or cause offence, under s 474.17 of the Criminal Code Act 1995 (Cth);46
- the Commonwealth identity crime offences dealing with identification information;47
- State stalking and intimidation offences — in New South Wales, for example, intimidation is an offence under s 13 of the Crimes (Domestic and Personal Violence) Act 2007 (NSW);48 and
- civil claims, such as defamation or breach of confidence.
The Government’s stated reason for creating a specific offence was that these measures were limited in scope, carried lower penalties, and were rarely used by prosecutors.
The new offences
The Act inserted ss 474.17C and 474.17D into the Criminal Code Act 1995 (Cth):49
- s 474.17C applies to making available, publishing or otherwise distributing the personal data of one or more individuals; and
- s 474.17D applies to the same conduct in relation to one or more members of a group.
The maximum penalty for doxxing an individual is six years’ imprisonment. Where the conduct is directed at a person because they are a member of a group, the maximum increases to seven years.50
The prosecution must prove beyond reasonable doubt that:
- the accused used a carriage service to make available, publish or otherwise distribute information;
- the information was personal data; and
- a reasonable person would regard the conduct as menacing or harassing.
For s 474.17D, it must also be shown that the conduct was engaged in wholly or partly because of the accused’s belief that the group is distinguished by race, religion, sex, sexual orientation, gender identity, intersex status, disability, nationality, or national or ethnic origin. It is immaterial whether the group is in fact so distinguished.51
‘Personal data’ is defined differently from ‘personal information’ under the Privacy Act, rather than more or less broadly. In the Criminal Code, personal data means information about an individual that enables the individual to be identified, contacted or located; under the Privacy Act, personal information extends to an opinion as well as information, and applies whether or not the information or opinion is true, but says nothing about contacting or locating a person. The non-exhaustive lists in ss 474.17C(2) and 474.17D(2) include names, photographs and images, telephone numbers, email addresses, online accounts, residential addresses, work or business addresses, places of education and places of worship.52
Because the offences sit in the Criminal Code rather than the Privacy Act, the Privacy Act exemptions do not apply: small businesses and journalists are not exempt, and a corporation may be liable as well as an individual.
Other jurisdictions
United Kingdom. There is no standalone doxxing offence, but the conduct may engage the Data Protection Act 2018 (UK), the Malicious Communications Act 1988 (UK), or the Protection from Harassment Act 1997 (UK).
United States. There is no general federal doxxing offence. Conduct may be prosecuted under anti-intimidation and stalking laws, subject to the First Amendment protection for publishing newsworthy information.
Enforcement and open questions
The effect of the new offences will depend on enforcement. Significant obstacles remain: perpetrators frequently reside outside Australia, conceal their identity, or engage in conduct that may not meet the ‘menacing or harassing’ threshold. The Act requires the Minister to cause an independent review of the doxxing measures to be undertaken. That review must commence as soon as practicable after the end of the period of 24 months starting at the commencement of the doxxing schedule, and those who undertake it must report to the Minister within six months of the review commencing.53
Biometrics and the Australian privacy framework
Biometric data describes and classifies measurable human characteristics — commonly fingerprints, facial features and voice patterns — and is used primarily for identification and authentication.54 In Australia, biometric information is ‘sensitive information’ under s 6 of the Privacy Act 1988 (Cth), and attracts additional protections in relation to its collection, use and disclosure.55
How biometric systems work
The most common methods of biometric authentication in everyday use are face and fingerprint recognition on smartphones and laptops.56 Biometric data is also increasingly used by online platforms and in advertising.
Captured biometric data is analysed by a verification system, which compares the biometric information recorded at login against data stored on the device. The system evaluates whether the two sets are sufficiently similar to confirm the user’s identity. Unlike a password or PIN, which requires an exact match between the input and the stored value, biometric systems rely on patterns and features and so allow for a degree of tolerance.57 ANZ, for example, operates a ‘Voice ID’ feature that uses a customer’s voice print to verify identity in phone banking,58 and the Australian Taxation Office uses voice authentication to verify the identity of callers to its help lines.59
Legal framework
The Australian Privacy Principles (APPs) apply to most businesses and platforms operating in Australia that use biometric systems. The APPs most directly engaged are:
- APP 3 (collection): biometric data, as sensitive information, must generally only be collected with consent;
- APP 6 (use and disclosure): collected data must only be used for the purpose for which it was collected, unless an exception applies;
- APP 11 (security): reasonable steps must be taken to protect biometric data from misuse, interference and loss; and
- APP 12 (access): individuals have a right to access personal information held about them.
Where an entity fails to comply, the Information Commissioner may seek civil penalties.60 These principles govern the collection, storage and security of biometric data used in straightforward authentication systems of the kind described above. Biometric data nonetheless raises distinct problems.
Biometric data cannot be reissued
Biometric characteristics are effectively static. Unlike a password, once a biometric template is compromised it cannot be revoked and replaced.
Consent
The APP 3 requirement that sensitive information be collected with consent is difficult to satisfy in practice, particularly where information about biometric collection is buried in dense privacy policies or is not disclosed at all.
OAIC determination on Bunnings (2024), and the Tribunal’s decision on review (2026)
The Australian Information Commissioner found that Bunnings Group Ltd interfered with the privacy of individuals by collecting sensitive biometric information through facial recognition technology in 63 stores in Victoria and New South Wales. The Commissioner found that Bunnings collected sensitive information without consent, failed to take reasonable steps to notify individuals that their personal information was being collected, and did not include required information in its privacy policy.61
On review, the Administrative Review Tribunal departed from the Commissioner’s finding that Bunnings had contravened APP 3.3, holding that Bunnings was entitled to rely on exemptions to the requirement to obtain consent for the limited purpose of combatting retail crime and protecting its staff and customers from violence, abuse and intimidation in its stores. The Tribunal affirmed the findings that Bunnings had contravened APP 1 and APP 5 by failing to give appropriate notice of its use of the technology and by not completing a formal, structured and documented risk assessment. The Commissioner did not appeal.62
Comparable litigation has arisen overseas. Meta settled proceedings in Illinois and Texas concerning the collection and use of facial data from users and non-users of Facebook and Instagram to train facial recognition systems, in each case under State biometric privacy legislation.63
The small business exemption
Section 6C of the Privacy Act exempts most small businesses from the Act’s obligations.64 Small businesses that deploy biometric systems therefore fall outside the framework that would otherwise govern the storage and protection of that data. The Privacy Act Review Report proposed removing the exemption, and the Government agreed in principle to its removal subject to further consultation (see 2023 Government response to the Privacy Act Review Report above).
The statutory tort and biometric data
The statutory tort for serious invasions of privacy, discussed at A statutory right to privacy above, is relevant to biometric data in two respects.
First, the tort operates independently of the Privacy Act’s regulatory framework. A plaintiff may bring a claim against any person, whether or not that person is an agency or an APP entity, so the small business exemption in ss 6C and 6D does not limit it.65 The unauthorised collection of biometric information by an individual or a small business may therefore be actionable even though it falls outside the Act’s regulatory obligations.
Second, the tort is actionable without proof of damage. The nature of any harm suffered remains relevant to whether the invasion was serious, but a plaintiff is not required to establish loss. Given that biometric identifiers are permanent and cannot be reissued, an unauthorised collection or disclosure of biometric data may be capable of amounting to a serious invasion of privacy.
Whether, and in what circumstances, the misuse of biometric data will meet the seriousness threshold has not yet been tested in an Australian court.
Government Surveillance
Surveillance is the monitoring of behaviour, activities, or other changing information, usually of people for the purposes of influencing/managing/directing/protecting them (Lyon 2007). For a glossary of commonly-used terms in surveillance studies, have a look at this open access book edited by Guy McHendry.
Surveillance is by governments for intelligence gathering, prevention of crime, protection of process/group/person/object or for investigation of crime.
The extent of government surveillance powers go to heart of issues about appropriate role of the state in our lives, including:
- Rule of law
- Liberal democratic
- Public safety and security
- Civil liberties and human rights (especially privacy)
Since 9/11, the War on Terror in Western countries has seen expansion of anti-terrorism and law enforcement surveillance powers in many countries.
Telecommunications (Interception and Access) Act 1979 (Cth)
This Act:
- Makes it an offence to intercept (listen to or record) a communication passing over a ‘telecommunications system’ without the knowledge of the person making the communication
- Also an offence to publish or retain a record of information gained in this way
- Allows access to communications content for law enforcement and national security purposes after obtaining a judicial warrant.
Telecommunications Act 1997
This Act imposes obligations on telecoms providers inc to provide assistance to law enforcement agencies for:
- enforcing the criminal law and laws imposing pecuniary penalties
- assisting the enforcement of the criminal laws in force in a foreign country
- protecting revenue
- safeguarding national security.
Exceptions to the Privacy Act
The Privacy Act 1988 (Cth) applies to most Australian government agencies, including the Australian Federal Police, Australian Border Force, and CrimTrac. However, certain intelligence and national security agencies are excluded from the Act:
- Office of National Assessments
- Australian Security Intelligence Organisation (ASIO)
- Australian Secret Intelligence Service (ASIS)
- Australian Signals Directorate (ASD)
- Defence Intelligence Organisation
- Australian Geospatial-Intelligence Organisation
- Australian Commission for Law Enforcement Integrity
- Australian Criminal Intelligence Commission
For these excluded organisations, the Inspector General of Intelligence and Security provides oversight and review of these agencies’ activities, ensuring their operations remain within legal bounds and maintain propriety
Data Retention
Law passed in 2015 to implement data retention scheme: Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 (Cth).
Telecommunications companies must retain and secure for 2 years a set of information:
- source and destination of a communication
- date, time and duration of a communication
- communication type
- location of communications equipment.
Retained data can be accessed without a judicial warrant. Under Chapter 4 of the Telecommunications (Interception and Access) Act 1979 (Cth), disclosure is authorised internally, by an authorised officer within the requesting agency, rather than by a court. Existing (historical) data may be sought under s 178 by the broad class of ‘enforcement agencies’; prospective data may be sought under s 180 only by a ‘criminal law-enforcement agency’, a category defined in s 110A to comprise the interception agencies together with the Department of Home Affairs, the Australian Securities and Investments Commission and the Australian Competition and Consumer Commission, plus any additional body the Minister declares under s 110A(3). Because ministerial declarations lapse and are renewed, the number is not fixed: the Department of Home Affairs reported that 20 criminal law-enforcement agencies made authorisations for prospective data in 2024–25, and 21 enforcement agencies made authorisations for existing data.66 Access to data for the purpose of identifying a journalist’s source additionally requires a Journalist Information Warrant.
The scheme remains in force, and has attracted sustained criticism. Civil society organisations — including Digital Rights Watch, the Human Rights Law Centre and Access Now — have described the regime as permitting mass surveillance without adequate safeguards, noting that the retained data has been sought for matters far removed from the serious crimes used to justify the scheme, and have called for access to be confined to serious offences and made subject to a warrant.67 In its statutory review of the regime, the Parliamentary Joint Committee on Intelligence and Security found that improvement was required to ensure the scheme’s proportionality, and recommended a series of changes to narrow and clarify it.68 The Law Council of Australia made submissions to similar effect.69 The scheme also diverges from the position in the European Union: the Court of Justice of the European Union invalidated the Data Retention Directive in Digital Rights Ireland,70 and subsequently held in Tele2 Sverige that European Union law precludes national legislation providing for the general and indiscriminate retention of traffic and location data.71
This section describes the position as at 2026. The data retention regime is subject to periodic statutory review; check for later developments before relying on it.
International surveillance laws: USA PATRIOT Act
The USA PATRIOT Act, officially known as the “Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001,” was a keystone in the national security enhancement strategy passed by the United States Government after the September 11, 2001 terrorist attacks. Its provisions have considerably broadened the surveillance and investigative authorities of federal agencies. It was intended to mitigate future attacks by giving the government broad authorities to track and access communications and financial data across international borders and within the US.
The Act has profound implications for data privacy, particularly in the context of cloud services. It grants US government agencies access to any kind of personal data stored by a US-based cloud provider, no matter the country of origin of the owner or where the data lies. This means that even if a business or individual outside the US chooses a cloud service that operates within the US or has headquarters there, their data could still be subject to scrutiny under the PATRIOT Act.
Sections 215 and 505 of the PATRIOT Act raise particular concerns for data privacy:
-
Section 215 (the “business records” provision) allows federal agencies to request any person or entity to hand over “any tangible things” relevant to a terrorism investigation. This section grants the government broad authority to collect a wide range of business records without requiring a court order. Importantly, according to the original version of the Act, this authority could be used to gather information in bulk, even if the data pertains to individuals not directly under investigation, raising significant concerns about overreach and privacy.
-
Section 505 authorises the issuance of National Security Letters (NSLs), which are administrative subpoenas that allow federal agencies to demand certain types of records from companies, such as telecommunication firms and internet service providers, without prior judicial approval. Unlike Section 215, NSLs are more targeted but come with a “gag order” that prevents companies from informing individuals about the government’s data request. This secrecy adds another layer of concern regarding transparency and the potential misuse of these powers.
The PATRIOT Act is criticised as undermining the ability of other countries to enforce their own data privacy laws, leading to legal complexities and confusion. This has implications for companies that handle sensitive or personal data and must comply with strict data protection regulations, such as the General Data Protection Regulation (GDPR) in the European Union, Personal Data Protection Act (PDPA) in Singapore, or Russian Federal Law on Personal Data (152-FZ). The PATRIOT Act’s provisions may conflict with such legislation.
Additionally, the Act raises ethical concerns about the balance between national security and individual privacy. Public awareness of these issues grew significantly after Edward Snowden’s 2013 revelations about the extent of US government surveillance, particularly the bulk data collection under section 215. Snowden’s disclosure further turned the public eye to such surveillance powers, eventually followed by legal reforms (the USA FREEDOM Act of 2015, which tried to limit some of the more controversial practices). While the USA FREEDOM Act curtails bulk data collection, many of the core provisions affecting cloud hosting, such as access to information stored by US-based providers, remain largely intact. This underlines ongoing ethical concerns of trading off national security against personal privacy, especially to the disadvantage of non-US citizens who are using US-based cloud services.
Privacy-enhancing technology
Data security and individual privacy rights are paramount considerations in the digital information age and an urgent global priority. Privacy-enhancing technologies (PETs) employ various measures to secure data by: (i) reducing or eliminating personal data, or (ii) preventing the unnecessary processing of personal data while preserving the functionality of the data system.72
In addition to traditional cryptographic techniques, corporations and other entities may utilise a variety of PETS to achieve these goals. These include data obfuscation, encrypted data processing, data accountability tools, and federated and distributed analytics. The integration of these emerging technologies promotes a privacy-by-design or default paradigm. This approach typically involves incorporating PETs into system infrastructure from the outset and modifying how organisations collect and use personal data.
In Australia, entities are indirectly encouraged to use PETs to meet their obligations under the Australian Privacy Principles (APPs) concerning personal information collection, retention, and handling.
Cryptography
Cryptography is a fundamental method for enhancing individual privacy and serves as the foundation for many data security iterations, including private and hybrid blockchains, virtual private networks (VPNs), and distributed database systems. For entities gathering, retaining and transmitting sensitive personal information digitally, it offers a safeguard to protect individuals from unauthorised access, interception and data tampering.
The widespread use of cryptographic encryption is attributed mainly to the uptake of Pretty Good Privacy (PGP) encryption programs. Encryption can enhance or undermine data protection, depending on how it is used. When individuals encrypt their personal information and retain the private key, they effectively maintain autonomy over disclosing their information. When an individual encrypts another person’s personal information using a public key and withholds the private key, it mirrors the basic operations of ransomware. For more information on ransomware in cybersecurity, see Simplilearn’s video.
Cryptographic encryption works by converting data into a ‘secret’ code, ensuring only authorised individuals may access, view and change the information contained within the data. Authorised individuals can use a cipher (a key) allowing the user to decrypt obfuscated data into its original format. The technology is interpolated into various messaging platforms such as Meta, Wickr or WhatsApp and remains a trusted security measure in the Wikileaks submission portal.
Cryptographic encryption requires three critical components:
-
Data that needs to be protected. This data could be confidential information such as a message, file, or other digital content.
-
A sender who possesses a public key. A public key is a cryptographic code that may be freely distributed and is used to encrypt the data. The sender utilises the public key to encrypt the data before sending it to the intended recipient.
-
The receiver of the encrypted data holds the corresponding private key. The private key is kept secret and is used to decrypt the received data that has been encrypted using the public key.
Third-party explainer: How Tor Works, from the ‘Mental Outlaw’ YouTube channel. This is general commentary from an independent channel, not an authoritative source. For the Tor Project’s own documentation, see About Tor Browser in the Tor Browser User Manual and the Tor Project support pages.
The Tor network
Tor — originally ‘the onion router’ — is one of the most widely used anonymity tools. It conceals a user’s IP address by relaying traffic through a series of volunteer-run nodes, encrypting each hop so that no single relay can see both the original source and the destination.73 The network distinguishes several node types:
- the guard node, which is the point of entry into the network;
- middle nodes, which sit between the guard and exit nodes, and through which a message may pass more than once;
- the exit node, through which traffic passes before returning to the open internet; and
- bridge nodes, a form of guard node that is not publicly listed.
Development began in the mid-1990s at the United States Naval Research Laboratory, with the aim of protecting government communications. Restricting the network to government and law enforcement users would have defeated its purpose: if every connection originated from an official, the anonymity set — the pool of users among whom any one user’s traffic is indistinguishable — would be trivially small. The network was opened to the public in 2002 for that reason.74 It is now maintained by the non-profit Tor Project, and is used both for anonymous browsing and for hosting anonymous services.75
Tor and Australian law
Tor engages Australian privacy and surveillance law in a number of ways. APP 2 provides that individuals must have the option of dealing with an APP entity anonymously or under a pseudonym, where lawful and practicable.76 APP 11.2 requires entities to take reasonable steps to destroy or de-identify personal information that is no longer needed.77
Those principles sit alongside obligations that run the other way. Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (Cth) requires carriers and carriage service providers to retain specified telecommunications data for two years.78 The Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth) empowers agencies to issue technical assistance and technical capability notices to communications providers, a scheme discussed at Law enforcement powers above.79 Tools such as Tor operate outside these schemes: they shift control over identification back to the user, which is the source of both their value to at-risk users and their attractiveness to offenders.
As at the time of writing, there is no Australian legislation prohibiting the use of anonymity tools such as Tor. Some jurisdictions, including China and Russia, have taken steps to block access to the network.80
Tor and the dark web
Tor is one of the principal means of accessing services that are not reachable through the open web, including sites using the .onion top-level domain.
A study that captured the traffic passing through a Tor exit node over six months found that most usage was directed at ordinary destinations: users spent much more time on social networking and e-commerce sites than on sites carrying illegal drug or pornographic content, and visits to legal sites vastly outnumbered visits to illegal ones.81 Journalists, whistleblowers, human rights workers and people living under censorship regimes use the network to communicate and report without exposing their identity or location.82
The same properties are also used to conceal serious offending, including the distribution of child sexual abuse material and trafficking in illicit goods. Australian courts have dealt with the network in several recent matters:
Director of Public Prosecutions (Cth) v XYZ (A Pseudonym) [2024] VCC 1188 — the offender used Tor to access and download child abuse material; investigators were able to recover the relevant browsing history from the seized device.
Aitken (A Pseudonym) v The King [2025] SASC 120 — a matter involving blackmail and threats to a school, in which forensic examination extended to the applicant’s VPN and Tor usage.
Attorney-General (Qld) v GFA [2025] QSC 19 — on an application under s 22 of the Dangerous Prisoners (Sexual Offenders) Act 2003 (Qld) concerning contraventions of an existing supervision order, the court amended that order to add a condition prohibiting the respondent from obtaining or using ‘devices, software, applications or web-based searches designed to … Anonymise or hide activity’, a category the condition defines as including ‘Virtual Private Networks (VPNs), Cache Cleaner applications and The Onion Router (TOR) Network’.
The first two of these cases illustrate a recurring point: anonymity technologies do not place users beyond the reach of investigation, because evidence is frequently recovered from the endpoint device rather than from the network itself. The third illustrates a different response — restricting access to anonymity tools as a condition of a supervision order.
Cryptocurrency and pseudonymity
A cryptocurrency is a digital asset used as a medium of exchange, recorded on a distributed ledger rather than administered by a central issuer.83 Transactions are recorded on a blockchain, which means that no single body controls issuance. Two features of that design matter for privacy law: issuance is not set by a central bank, and transactions are pseudonymous rather than tied to a verified identity.84 Pseudonymity is not the same as anonymity — public blockchains record every transaction permanently, and analysis of that record is itself a surveillance technique — but it substantially raises the cost of attributing a transaction to a person.
Illicit use and the limits of attribution
The pseudonymity of public blockchains has been associated with use of cryptocurrencies for illegal trade, money laundering and evasion of capital controls.85 One widely cited study estimated that around one quarter of bitcoin users, and close to half of bitcoin transactions, were associated with illegal activity.86
Estimates of the proportion of cryptocurrency activity associated with crime vary widely between studies and depend heavily on the classification method used. The figures above are drawn from a single 2019 study of bitcoin and should not be treated as a settled measure, or as applying to cryptocurrencies generally or to the present day.
Silk Road
Silk Road was an online marketplace that used bitcoin to facilitate trade in illicit goods and services. It was shut down by United States federal law enforcement in October 2013, in an investigation led by the Federal Bureau of Investigation, and the operator, Ross Ulbricht, was subsequently convicted and sentenced to life imprisonment.87 Ulbricht was granted a full and unconditional presidential pardon on 21 January 2025.88 The seizure demonstrated that pseudonymous marketplaces are not beyond the reach of law enforcement, and remains the standard illustration of both the attraction and the vulnerability of that model.
Attribution remains difficult. Mixing services such as CoinJoin combine balances from multiple addresses and redistribute them to new addresses, obscuring the origin of funds.89 Privacy-focused cryptocurrencies are designed to conceal transaction details at the protocol level rather than relying on mixing.90 The result is that only a small fraction of the value moving through illicit marketplaces has been positively identified as such.
Regulation
The proper use of PETs generally falls within the mandate of the Office of the Australian Information Commissioner (OAIC) to ensure organisations take reasonable steps when handling personal information and maintain acceptable data retention practices in compliance with the Privacy Act 1988 (Cth) and other relevant laws. The regulatory framework in Australia encourages but generally does not expressly require organisations to use privacy-enhancing technologies (PETs).
Law enforcement powers
In Australia, law enforcement is conferred broad powers to compel certain private intermediaries to provide ‘technical assistance’ to garner access to encrypted communications concerning criminal investigations. Under the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (TOLA Act), service providers must provide law enforcement access to decrypted communications or decryption tools, stripping anonymity or privacy of communications. These laws remain controversial globally and perhaps best explained in Tim Cook’s open letter to customers in 2016 following the company’s refusal to comply with FBI requests to remove cryptographic features. The TOLA Act arguably undermines the essential security features of encryption and infringes upon individual privacy rights.
OAIC powers
The regulatory powers conferred on the OAIC govern the use of PETs by monitoring government and private entities’ compliance with the APPs set out in Schedule 1 of the Privacy Act. The OAIC may commence an investigation based on individual complaints or the Information Commissioner’s initiative regarding potential breaches. Where entities report a data breach per their obligations under the Notifiable Data Breaches Scheme (NDBS), the OAIC will assess the data breach and provide advice or further investigate the matter to mitigate and prevent further impacting personal privacy.
The investigative powers conferred on the OAIC provide authority to compel the provision of information regarding data access, record-keeping, and internal policies. The OAIC may conduct Privacy Assessments to evaluate an entity’s compliance with the APPs. Where the OAIC determines non-compliance with or a breach of the Privacy Act, it may order data handling practices to cease or change, issue infringement notices, or apply to the Federal Court seeking orders of injunctive relief and financial penalties for repeated and serious breaches.
The OAIC may also publish investigation outcomes and issue public notices regarding potential non-compliance, breaches and privacy issues associated with the practices of specific organisations. This ensures transparency, alerting the public to the privacy risks associated with organisations, and acts as a deterrent for other organisations lacking or inappropriately handling personal information. For example, in the wake of the Facebook and Cambridge Analytica political data-sharing controversy,91 the OAIC investigated with the Commissioner, bringing proceedings against Facebook for serious and repeated interferences with privacy. While pending determination, the OAIC has published the particulars of the allegations highlighting breaches of APP 6 and 11.
Case studies
My Health Records Act 2012 (Cth) and Health Identifiers Act 2010 (Cth)
My Health Records facilitates identifying and maintaining patient records, enabling informed communication between healthcare providers regarding individual healthcare recipients. An individual health identifier (IHI) is assigned to a collection of personal information from those recipients per s 7(3) of the Health Identifiers Act 2010 (Cth) (HI Act) for use in the My Health Record data system. Personal information such as names, addresses, dates of birth, government identifiers, and the resultant IHI constitutes personal information under s 33C(1)(a) of the Privacy Act.
Healthcare providers must also take reasonable steps to protect IHIs from unauthorised data use, misuse, or loss (s 27). In addition to the range of compliance obligations regarding personal information under the Privacy Act, the HI Act sets a higher privacy standard, making individuals liable to face criminal and civil penalties for unauthorised disclosures and data misuse (s 26). Concurrently, a breach of the HI Act will interfere with the affected parties’ privacy for any regulatory action taken under the Privacy Act.
The OAIC’s role involves investigating privacy matters arising from data handling personal information in the My Health Record system. Part V of the Privacy Act sets out the OAIC’s investigative powers. However, the Information Commissioner has a broader power under s 73(4) to “do all things necessary or convenient to investigate” contraventions of the My Health Records Act.92
While seemingly broad, commentary following My Health Record system audits shows it lacked proper management of shared cyber security risks. Specifically, there was no assurance framework monitoring third-party software connecting to the system nor a means to monitor compliance with the security requirements per the legislation.93 At that time, the My Health Record system boasted a robust core infrastructure, though third-party applications, such as a Microsoft OS update, could undermine the system’s security.
Children’s online privacy and sharenting
Editor’s note: needs edit – not sure about the neologism.
Many children have digital footprints before they take their first steps, leading to concerns around privacy breaches and the exacerbation of privacy risks by the “sharing” practices of parents and guardians online. The term “sharenting” refers to a parent/guardian sharing photos, videos, personal stories, and other updates about the child’s daily activities, such as eating, sleeping, bathing, and playing. Sharenting invokes a tension between the child’s interest in privacy and autonomy over their digital identity, and the parent/guardian’s right to freedom of speech and to have control over the upbringing of their children.
Risks associated with sharenting
As information cannot easily be erased once shared online, the harms of sharenting may include:
- identity theft
- resharing pirated information on predator sites
- sharing psychosocial information that should remain private, and
- sharing revealing or embarrassing information that may be misused by others.
Long-term consequences can include a negative impact on the emotional, social and intellectual development of a child, as they may grow up to resent their parents, be victim to bullying and harassment, or have to rebuild their digital identity.
Studies conducted by the Australian Government’s eSafety Commission found approximately 50% of images shared on paedophile sites were taken from social media. The new phenomenon of “Kidfluencers” adds an additional element to this risk. A recent controversial instance concerned a 3-year-old girl, Wren Eleanor, whose mother posted videos of her on their TikTok account, which over time accrued over 17 million followers. As the videos gained attention, people started the notice the ‘creepy comments’ and mass amounts of times the videos had been saved by other anonymous users, and concerns were expressed that the mother may have been exploiting her child for money.
Legislation governing the privacy rights of children
The law leaves children’s online privacy and sharenting largely unregulated as current laws do not address or govern the publication of a child’s image or information online. According to the United Nations Convention on the Rights of the Child, a child means every human under the age of eighteen, but in Australia, the Privacy Act 1988 protects an individual’s personal information regardless of their age. It doesn’t specify an age after which an individual can make their own privacy decision, but for their consent to be valid, an individual must have capacity to consent. Article 16 of the UN Convention on the Rights of the Child, states that:
“No child shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, nor to unlawful attacks on his or her honour and reputation and the child has the right to the protection of the law against such interference or attacks.”
Social media platforms are regulated in collecting and handling data on children’s accounts, but individuals’ digital privacy is left to user discretion. Hence a child’s privacy can still be overruled by their parents’ freedom of speech and discretion.
There have been attempts by other countries to implement specific regulations related to the sharing of children’s personal data, but no countries had adopted laws that protects children’s privacy through the lens of rights to their images until earlier this year. In France, the Law no. 2024-120 of February 19, 2024 (“Children’s Image Rights Law”), was implemented with aims to tackle risks of sharenting, by completing measures to limit risk-creating behaviour and enshrine children’s right to privacy and facilitate the exercise of rights which protect minors. This new law is the first law of its kind and sets the precedent for other countries to do the same, to ensure the safety of children and the risks associated with their privacy and image are protected.
Content regulation and the limits of the current framework
The risks of parental posting differ from the other harms addressed in this textbook — cyberbullying, adult cyber abuse and image-based abuse — in that they usually arise from ordinary and well-intentioned conduct rather than from an intent to harm. Four features distinguish them:
- Consent and autonomy: a child cannot give informed consent to the permanent digital record created by a parent’s posts, and may bear the consequences of that record into adulthood.
- Exploitation risk: ordinary family content can be copied and recirculated. Features that allow one user to build on another’s video, such as duets and stitches, make redistribution trivial and place the material well outside the original poster’s control.
- Commercialisation: where a child’s online presence is monetised, the child is the source of the income but has no legal interest in it. France requires income earned by child social media performers to be held in trust and regulates their working conditions;94 Australia has no equivalent framework.
- Algorithmic amplification: recommender systems can distribute a video far beyond the audience a parent anticipated, without any action by a third party.
The Online Safety Act 2021 (Cth) operates on a co-regulatory model, under which industry bodies draft codes that the eSafety Commissioner may register. The mechanisms most relevant to children are removal notices for cyber-bullying material targeted at an Australian child,95 the Basic Online Safety Expectations,96 and the social media minimum age obligations discussed at Social media minimum age.
Each of these operates on material after it has been published, or on a platform’s general systems, rather than on the decision to post. None restricts a parent from publishing images of their own child. The scheme’s reach is also territorially constrained: in eSafety Commissioner v X Corp the Federal Court read the ‘reasonable steps’ required by a removal notice narrowly, and declined to construe the power as authorising global removal.97 The same reasoning would limit the Commissioner’s ability to secure worldwide removal of redistributed material involving children.
United Kingdom. The Online Safety Act 2023 (UK) created new communications offences, including cyberflashing and encouraging serious self-harm, directed at the conduct itself rather than at post-publication removal.98
Two gaps therefore remain in the Australian framework. There is no direct regulation of parental publication of children’s images, whatever the long-term consequences for the child’s privacy or autonomy; and there is no framework governing the commercial exploitation of a child’s online presence of the kind that exists in some comparable jurisdictions.
Legislative reform on the privacy rights of children
The Privacy Act 1988 (Cth) protects the personal information of adults and children alike, without distinguishing between them. That is set to change. The Privacy and Other Legislation Amendment Act 2024 (Cth) requires the Office of the Australian Information Commissioner (OAIC) to develop a Children’s Online Privacy Code.99
The Children’s Online Privacy Code
Section 26GC of the Privacy Act requires the Code to be developed and registered within 24 months of Royal Assent, which means it must be registered by 10 December 2026.100
The OAIC’s issues paper explains the rationale: children are particularly vulnerable to the misuse of their data and may not fully understand the privacy implications of their online activity, and existing privacy laws have not kept pace with changes in digital engagement or the scale of data collection.101
The Code will be an APP code under s 26C of the Privacy Act. It will apply to APP entities and will set out how online services must comply with the Australian Privacy Principles when providing services that are used, or are likely to be used, by children.102 It may impose additional requirements, provided they are within scope and consistent with the APPs. Development includes consultation with children, parents, relevant organisations, and industry and academic stakeholders.103
The OAIC has indicated that, where appropriate, the Code will draw on the United Kingdom’s Age Appropriate Design Code.104
The UK Age Appropriate Design Code
United Kingdom. The Age Appropriate Design Code, often called the Children’s Code, is a statutory code of practice. It was laid before Parliament on 11 June 2020, issued on 12 August 2020 and came into force on 2 September 2020, with a twelve-month transition period in which providers were to bring their processing into line with its standards by 2 September 2021. It contains 15 standards that online services must follow to protect children’s data.105 The standards draw on the United Nations Convention on the Rights of the Child; the first standard, that the best interests of the child should be a primary consideration in designing and developing online services likely to be accessed by a child, reflects art 3 of the Convention.
The Code is issued under the Data Protection Act 2018 (UK) and operates alongside the UK General Data Protection Regulation and the Privacy and Electronic Communications Regulations. It applies to ‘information society services’ likely to be accessed by children — services normally provided for remuneration, at a distance, by electronic means, and at the individual request of a recipient. Because that definition is broad, most online services fall within its scope. Services that do not comply may face enforcement notices and financial penalties.
The approach has been followed elsewhere, including in California, which enacted a version of the code in 2022. The Californian Act has never taken full effect. It was challenged before it commenced and its central data use restrictions and dark patterns prohibition remain preliminarily enjoined: in March 2026 the Ninth Circuit affirmed the injunction as to those provisions, while vacating it as to the coverage definition and the age estimation provision and remanding for further proceedings. The litigation is continuing.106
The Australian Code is still in development and will not be registered until December 2026. This section describes the framework as it presently stands; the substantive obligations will not be settled until the Code is made.
The Right to be Forgotten
What is the Right to be Forgotten?
The right to be forgotten (also known as the ‘right to erasure’) grants individuals the ability, in certain circumstances, to have their personal and private information removed from the internet, where it no longer serves a significant public interest. Exercising the right to be forgotten removes the subject information from search engine results. Although it’s not completely ‘deleted’, it significantly reduces the visibility and accessibility of the information. There have been recent calls for Australia to introduce a ‘right to be forgotten’.
The Right to be Forgotten in Europe
In the 2014 case of Google Spain SL v Agencia Española de Protección de Datos (Google Spain), the right to be forgotten was formally recognised as a fundamental right for Europeans.
Mr Mario Costeja Gonzalez filed a complaint against Google Spain and the Spanish Data Protection Agency, because searching his name on Google revealed a link to a 1998 newspaper article, which described information about his personal debts. Gonzalez argued that the information was irrelevant and infringed on his personal privacy. In its decision, the European Court of Justice ruled in Gonzalez’s favour. The court stated that individuals had the right to request the removal of links to personal information when the information was ‘inadequate, irrelevant, no longer relevant, or excessive’. This gave rise to the right to be forgotten (also known as the right to erasure) for Europeans, which prior to the decision, was far more theoretical and lacked legal definition. The General Data Protection Regulation (GDPR) now provides a formal right to erasure in art 17: under art 17(1) a data subject may require a controller to erase personal data where one of the listed grounds applies, including that the data are no longer necessary for the purposes for which they were collected, that the data subject has withdrawn the consent on which the processing was based and no other legal ground applies, that the data subject has objected to the processing under art 21 and there are no overriding legitimate grounds, or that the data have been unlawfully processed.107 The right is not limited to search engine results — that is the particular application worked out in Google Spain — and it is subject to the exceptions in art 17(3), which include processing necessary for exercising the right to freedom of expression and information.
The GDPR does not apply only to processing carried out within the European Economic Area. Article 3(1) applies the Regulation to processing in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing itself takes place in the Union. Article 3(2) expressly extends the Regulation to controllers and processors not established in the Union, where the processing relates to the offering of goods or services to data subjects in the Union (whether or not payment is required), or to the monitoring of their behaviour as far as that behaviour takes place within the Union.108 An Australian business with no European establishment may therefore fall within the GDPR if it targets or tracks people in the Union.
Beyond its formal reach, the Regulation has also influenced practice elsewhere. A survey conducted six months after the GDPR came into force reported that, in 2018, 74 per cent of organisations surveyed in Australia already employed a Data Protection Officer — a role the GDPR requires of many organisations to which it applies.109
Australia and the Right to be Forgotten
The case of Google Spain and the enaction of the GDPR indicates that privacy protection for individuals with unequal bargaining power against large corporations, is a significant policy concern in the European Union. Whilst many of these privacy issues are similarly addressed by Australian policymakers and courts, Australians do not have the right to be forgotten.
Instead, Australians rely on protection from the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and traditional remedies, such as the tort of defamation. Although APP 11 and 13 require the destruction, de-identification or correction of information, Australia does not come close to providing adequate protection for citizens in comparison to the GDPR. Currently, there is minimal legislative guidance as to how and what steps should be taken by entities to remove personal information. On the other hand, whilst the tort of defamation may help remove slanderous content, it cannot address privacy concerns regarding harmful, yet true, public information. Defamation is also limited by practical issues, for example, the difficulty of enforcing a judgment when the online content is posted by an unknown or foreign individual. This has drawn sharp criticism from Australians seeking stronger safeguards regarding the handling of their personal information.
Australian Common Law
In the South Australian case of Duffy v Google Inc, whilst not directly referring to the right to be forgotten, the Supreme Court held that because Google Inc had published the personal data of Dr Duffy, they were responsible for its removal. This was on the basis that Google was liable as a secondary publisher of snippets and hyperlinks which carried ‘pejorative connotation[s]’ and defamatory meanings. It still remains to be seen whether higher courts in Australia adopt this position in similar cases.
Legislative Reform
In 2019, the Attorney-General released its report on the Privacy Act 1988 (Cth) and proposed the adoption of a right to be forgotten into Federal legislation. In 2023, the Australian Government released its response to the Attorney-General’s Privacy Act Review Report. The Government’s response concluded that it was necessary to overhaul Australia’s privacy laws, with the ultimate goal to ensure that the Privacy Act remained fit for purpose in the ever-changing digital age. Within the response, the Government announced a number of proposed updates and agreed in-principle at proposal 18.3 that Australians required the individual right to request an entity to delete (or de-identify) personal information, with the exception of purposes required for law enforcement and national security:
Proposal 18.3
Introduce a right to erasure with the following features:
a) An individual may seek to exercise the right to erasure for any of their personal information.
b) An APP entity who has collected the information from a third party or disclosed the information to a third party must inform the individual about the third party and notify the third party of the erasure request unless it is impossible or involves disproportionate effort. In addition to the general exceptions, certain limited information should be quarantined rather than erased on request, to ensure that the information remains available for the purposes of law enforcement.
In September 2024, the first tranche of the Government’s proposed Privacy Act reforms were announced. However, proposal 18.3 was not amongst the selected reforms put forward in the Privacy and Other Legislation Amendment Bill 2024. There remains no right to be forgotten in Australia.
The SPAM Act
Video Overview of the SPAM Act by Anna Hall
The SPAM Act 2003 (Cth) prohibits the sending of unsolicited commercial electronic messages with an Australian link. A message has an Australian link if it originates or was commissioned in Australia, or originates overseas but was sent to an address accessed in Australia.
Electronic messages include Email, SMS and instant messaging. An electronic message is commercial if it offers, advertises or promotes the supply of goods, services, land or business or investment opportunities, or if it advertises or promotes the supplier of any of these things.
Messages are SPAM if they are sent without the prior consent of the recipient. A single message may be SPAM; messages do not have to be sent in bulk.
To avoid contravening the SPAM Act, electronic messages should only be sent with the consent of the recipient, must contain clear and accurate identification of the sender and how they can be contacted, and should include an unsubscribe facility.
The financial penalties for breaching the Spam Act are expressed in penalty units, the value of which is indexed under s 4AA of the Crimes Act 1914 (Cth). Section 25 of the Spam Act tiers the maximum penalties according to whether the contravener is a body corporate, and whether it has a prior record in relation to the same civil penalty provision. Where a body corporate commits two or more contraventions of s 16(1), (6) or (9) — the core prohibitions on sending unsolicited commercial electronic messages — on a particular day, the total penalty must not exceed 2,000 penalty units if it has no prior record, or 10,000 penalty units if it does. The equivalent ceilings for a person who is not a body corporate are 400 and 2,000 penalty units. At the penalty unit value of $364 that applies to contraventions committed on or after 1 July 2026, the two body corporate ceilings are $728,000 and $3.64 million.110
After an investigation by the Australian Communications and Media Authority (ACMA) found Pizza Hut sent 5,941,109 text and email messages between January 2023 and May 2023 to customers who had not withdrawn consent or not consented to receive those messages. The investigation also found that during that period they had sent 4,364,971 messages without providing an option for customers to unsubscribe. ACMA had previously issued 15 compliance alerts to Pizza Hut, with Pizza Hut eventually paying over $2 million for breaching the Spam Act 2003 (Cth). In addition to the penalty, ACMA accepted an enforceable undertaking from Pizza Hut, which required the company to implement auditing, reporting and record-keeping measures, retrain all staff responsible for commercial electronic messages, and appoint an independent consultant to review its policies and practices for sending commercial electronic messages.
The Do Not Call Register
The Do Not Call Register Act 2006 (Cth) regulates unsolicited telemarketing calls and marketing faxes.111 It gives individuals a mechanism to opt out of unsolicited telemarketing, while preserving exemptions for organisations making calls in the public interest. It sits alongside the Spam Act 2003 (Cth), which regulates unsolicited commercial electronic messages, and forms part of Australia’s broader privacy framework.
Before the Act, telemarketing was largely self-regulated through voluntary industry codes. That approach was widely regarded as ineffective: there were no compulsory standards, no dedicated enforcement authority, no formal complaints mechanism, and considerable uncertainty among both telemarketers and consumers about their rights and obligations. Research published by The Australia Institute in December 2008 — two and a half years after the Act commenced, and directed at measuring the register’s effect — reported that Australians still received an average of 8.5 unsolicited telemarketing calls a month, and that two in three (64 per cent) of those surveyed believed telemarketing should be banned outright.112
How the register works
The register is established under Part 3 of the Act and operates on an opt-out basis. An Australian number is eligible to be entered on the register only if it is used or maintained primarily for private or domestic purposes, exclusively for transmitting or receiving faxes, or exclusively for use by a government body, or if it is an emergency service number.113 Once a number is on the register, it is unlawful to make a telemarketing call or send a marketing fax to it unless an exemption applies.114
Sections 5 and 5B define a telemarketing call and a marketing fax respectively: a voice call or fax to an Australian number where the purpose is to offer, advertise or promote goods, services, land, or business or investment opportunities. The definition extends to soliciting donations.115 Telemarketers must wash their calling lists against the register, and are responsible for removing listed numbers within 30 days. The Australian Communications and Media Authority (ACMA) administers the register and handles complaints.
Exemptions
Consent. The prohibition does not apply where the relevant account-holder, or a nominee of the account-holder, consented to the call or fax.116 Consent means express consent, or consent that can reasonably be inferred from the conduct and the business and other relationships of the person concerned.117 Express consent that is not expressed to be for a specified period or an indefinite period is taken to be withdrawn three months after it was given, and consent may not be inferred from the mere fact that a number has been published.118
Public interest and constitutional exemptions. Schedule 1 defines a class of ‘designated telemarketing calls’ that are exempt from the prohibition, each subject to further conditions set out in the Schedule. The categories are calls authorised by a government body or a registered charity; calls authorised by a registered political party, an independent member of parliament or a candidate for the purpose of electoral or political fund-raising; and calls authorised by an educational institution to a private or domestic number connected with a current or former student.119 The rationale is that these callers are either non-commercial or serve a public function; the exemptions represent a legislative judgement about where individual privacy gives way to public communication.
Enforcement
ACMA’s enforcement powers are spread across several sources. Part 4 of the Act provides for civil penalties, which ACMA may seek in the Federal Court.120 Formal warnings for a contravention of a civil penalty provision are dealt with by s 40, and infringement notices by Schedule 3.121 Investigations, information-gathering and enforceable undertakings are provided for not by this Act but by Parts 26, 27 and 31A of the Telecommunications Act 1997 (Cth).122 Maximum penalties are tiered according to whether the contravener is a body corporate and whether it has previously contravened the same provision, and are calculated by reference to each day on which contraventions occurred. ACMA publishes the current maximum figures: infringement notice penalties of up to $222,000 per day, and court-imposed civil penalties of up to $2.22 million per day.123
Regulations and industry standards
The Do Not Call Register Regulations 2017 (Cth) create further exemptions. Section 5(7) of the Act allows the regulations to declare specified kinds of voice calls not to be telemarketing calls, and the regulations do so for product recalls, fault rectification, appointment rescheduling and reminders, payment calls, solicited calls, and calls that are not answered by the intended recipient.124 These carve-outs allow operationally necessary or safety-related calls to be made without prior consent. Section 39(4) allows the regulations to specify when an individual may be treated as a nominee, which matters where several people share a telephone number but are not all account holders.
The Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 (Cth) is a legislative instrument made under s 125A(1) of the Telecommunications Act 1997 (Cth) rather than under the Do Not Call Register Act. It applies to all telemarketing and research calls in Australia, whether or not the number is on the register.125 Unless the person called has given express prior consent to being contacted at other times, telemarketing calls may be made only between 9:00 am and 8:00 pm on weekdays and between 9:00 am and 5:00 pm on Saturdays, and not at all on Sundays. Research calls are treated differently: they may be made until 8:30 pm on weekdays, and on Sundays between 9:00 am and 5:00 pm. Neither kind of call may be made on any of seven named national public holidays — New Year’s Day, Australia Day, Good Friday, Easter Monday, Anzac Day, Christmas Day and Boxing Day — or on a weekday holiday given in lieu of one of them.126 Callers must identify themselves and the organisation they represent, state the purpose of the call, provide contact details, and ensure a return number is displayed and answerable during business hours. Callers must not act in a manner that is unreasonable, disruptive or inconvenient, including by making repeated calls in a short period.
Privacy Protection in India
Constitution
Art 21 Constitution of India ‘No person shall be deprived of his life or personal liberty except according to procedure established by law.’
There is no express provision for the right to privacy in the Constitution of India. Over the past 60 years, there was a divergence of opinion as to whether the right to privacy is a fundamental right in India, resulting in inconsistent judgments being laid down.
In 2017, it was unanimously held in Justice KS Puttaswamy (Retd) v Union of India & Ors that the right to privacy is protected as a fundamental constitutional right under the right to life or personal liberty in Art 21 of the Constitution of India. This case serves as a landmark judgment and it explicitly overrules previous judgments where it was held that there is no fundamental right to privacy.
The right to privacy under the Indian Constitution is not an absolute right. An invasion of personal liberty must pass through the 3 fold test of legality, necessity, and proportionality.
Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules 2011
The Rules is a subordinate legislation which regulates the collection and disclosure of information by any bodies corporate. It provides for a consent requirement where businesses must obtain consent in writing through letter or fax or email from the provider of sensitive personal data or information before any collection of such information. Businesses must take reasonable steps to ensure that the person has sufficient knowledge regarding the collection.
The rules also control the disclosure and transfer of information. They are permissible in cases where prior permission is obtained from the provider or when it is necessary for the performance of the lawful contract between the business and the provider of information.
Although the implementation of security practices and standards are not mandatory under the Rules, in the event of an information security breach, businesses are required to demonstrate that they have implemented security control measures.
Digital Personal Data Protection Act 2023
Once fully implemented, the Digital Personal Data Protection Act 2023 will supersede the Information Technology Rules 2011 described above. The Act reflects the decision in Justice KS Puttaswamy (Retd) v Union of India & Ors and marks a significant shift in India’s privacy law. Its purpose is to regulate the processing of digital personal data, recognising both the individual’s right to safeguard their personal data and the need to process such data for lawful purposes.127
The Digital Afterlife
‘Digital afterlife’ refers to a continuation of an active or passive digital presence after a person’s death. It is a virtual space where information, assets, legacies, and digital remains reside as part of the cyber soul. Digital remains are “the digital content and data which was accumulated and stored online during our lifetime that reflect our digital personality and memories.” When internet users pass away, their digital remains may still be used by the living. For instance, the living may communicate to chatbots and avatars created by artificial intelligence (AI) that adopt characteristics of the deceased based on algorithms, and an executor of a deceased estate may deal with digital assets and social media accounts can be ‘memorialised’.
Ethical concerns have been raised about having individuals immortalised in the digital space, however, discourse regarding the legal implications of this emerging issue has remained limited.
AI and the Digital Afterlife Industry
The internet has become a space where the dead and the living co-inhabit. The number of dead accounts online is expected to surpass the living population by the end of this century. Projects including LifeNaut, Eternime, Replika, Project December powered by OpenAI, and ETER9 have emerged to take advantage of the new Digital Afterlife Industry (DAI). These social networks utilise AI machine-learning technology, which allows the AI to recognise patterns in user behaviour and data to digitally replicate the deceased. DAI is defined as an umbrella term encompassing “any activity of production of commercial goods (or services) that involves online usage of digital remains”. An example is two-way communication with AI chatbots and avatars impersonating the deceased (also known as ‘griefbots’ or ‘deadbots’).
For example, the AI in ETER9 creates a virtual counterpart to users (known as ‘Niners’) that learn and mimics the users’ online behaviour. These counterparts can interact online autonomously, i.e. post, comment and ‘like’, whilst assuming the user’s personality and characteristics, even after the biological user has passed. Some people communicate with these deceased’s counterparts to process grief. However, once users of these projects die, they no longer have control over their data and posthumous self, which has been permanently left on the internet to be consumed by the algorithm.
Post-mortem Privacy Protection
Issues that arise are the current lack of regulation for DAI companies such as ETER9 and the concern for an individual’s posthumous privacy protection. The notion of ‘post-mortem privacy’ (PMP), suggests that privacy, personal data and testamentary freedom forms part of a person’s autonomy and should be respected the same way as a physical body. PMP has been conceptualised as ‘the right of a person to preserve and control what becomes of his or her reputation, dignity, integrity, secrets or memories after death’. PMP emphasises the importance of a person’s control over their data after death. However, the right to privacy does not typically apply to deceased persons.
The General Data Protection Regulation (GDPR), introduced in 2014 by the European Union, provides the right to be forgotten online with the aim of “protect[ing] fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data”. ‘Natural persons’ does not include dead persons. Similarly, the Australian Privacy Act 1988 (Cth) does not extend the right to be forgotten to the deceased. However, there have been some instances where the possibility of providing privacy protection to the deceased has been shown. Section 9 of the Personal Data Protection Act 2018 of Estonia provides that the consent of processing personal data is “valid during the lifetime of the data subject and for 10 years after the death of the subject matter.” This approach may be considered by common law countries in the future.
Allowing AI to utilise the digital remains of deceased people might also be considered a violation of their dignity. However, the protection of an individual’s dignity is currently only recognised in common law (i.e. against defamation) and does not extend post-mortem.
While, PMP is currently not recognised under succession laws or privacy, an individual could clarify their intentions of their digital assets by way of social media providers’ online tools (eg social media legacy contacts or similar) or testamentary dispositions.
Social Media and Digital Remembrance
Social media platforms are also part of the DAI, with some allowing inactive profiles to remain as a place of remembrance for the deceased. This has been described as ‘online cemeteries’. In 2009, Facebook introduced a legacy contact function, which allows users to appoint a person to manage their memorialised main profile or have their account permanently deleted. The legacy contact may post a final message, respond to friend requests, and update the profile photo; however, they are unable to access the account and the user’s private messages. Accounts on Instagram may also be memorialised, with the word ‘Remembering’ appearing next to the deceased’s profile name. People can also appoint an ‘Inactive Account Manager’ for their Google account.
Digital Assets and the Law
Editor’s note: check overlap on discussion on digital goods and discusion on EULAs.
Digital assets are described as ‘any digital file on a person’s electronic device as well as any online accounts and memberships’. These assets include (but are not limited to) email accounts, social media accounts, digital photos, digital videos, cryptocurrency and online subscription accounts. Digital assets, to be identified clearly, can be categorised into different kinds of value. Nonetheless, the asset can be categorised into more than one value.
Digital assets can have financial, sentimental, social and intellectual value. Digital assets with financial value include bank accounts and cryptocurrency. These assets have a definite monetary value. Digital assets with sentimental value do not have monetary value, but rather sentimental in nature such as photographs and videos. Digital assets with social value include social media platforms where users have curated their accounts which allows them to connect with new people and portray their lives. Digital assets with intellectual value include emails, blogs, social media posts (written and visual material) that is published material. However, an asset with intellectual value may become a liability if the published material is defamatory to another individual. A deceased person cannot be sued; however, an estate of a deceased person can be sued if their published material is libel.
Currently, there is a lack of guidelines in Australia for how someone can access a deceased’s digital assets. The United States introduced the Revised Uniform Fiduciary Access to Digital Assets Act 2015 and Canada enacted a similar legislation in 2016 called the Uniform Access to Digital Assets by Fiduciaries Act. These laws authorise a representative to access digital assets if that power was expressed in the deceased’s will or other legal document such as a power of attorney. In 2022, the Australian Attorney-General’s Department released the Privacy Act Review Report endorsing the introduction of an access scheme for digital records. The Australian Government is yet to implement the recommendations in this report.
Digital Assets and Succession
In Australia, there are no laws that require testamentary acts to include digital assets, such as what directions the executor is given to either continue or delete social media profiles, online subscriptions or emails. It is up to the discretion of solicitors to raise what digital assets the testator owns as well as discussing with the client that they should provide their executor with their passwords upon their death to allow the executor to access and close or manage accounts. The NSW Law Reform Commission (NSWLRC) published a report ‘Access to Digital Records Upon Death or Incapacity’ in 2019 that thoroughly discussed amendments that need to be made to the current succession laws and estate laws to reflect digital assets, and to provide education to legal practitioners to assist clients in their decision-making when preparing their testamentary dispositions and providing their directions to their executor/s, trustees, guardians and attorneys.
The NSWLRC conducted two surveys to understand how digital assets should be dealt with upon death or incapacity. The first survey was asking the public “what should happen to your social media when you die?”, and the second survey was asking legal practitioners 43 questions ranging from “do you practice estate planning” and “is advising personal representatives about administering deceased estates part of your practice?”. The results concluded that not many people have thought about their digital assets.
The results can be found here.
Digital assets and digital presence
The eSafety Commissioner distinguishes two kinds of digital content that survive a person’s death.128
Digital assets are things a person has acquired or holds online — purchased media, domain names, accounts and the credentials that control them. Whether an asset can pass to another person on death is frequently determined not by succession law but by the provider’s terms of use, which commonly limit ownership and transferability. The relationship between those terms and the general law of digital goods is discussed at Digital Products and Consumer Rights below.
Digital presence is the persona built up through posts and interactions, including with people the user has never met.129 A person’s presence continues to change after death: relatives and friends may add to it by reposting, tagging or uploading new material, so the footprint is not fixed at the moment of death and is not within the deceased’s control.130
Research on estate planning suggests that this is poorly understood. Studies of digital asset planning literacy find that a minority of people appreciate that digital assets are treated differently from physical property on death, and that planning generally begins late in life, which leaves the question to be resolved between family members and providers after the fact.131
Digital grieving and AI recreation
The use of artificial intelligence to recreate a deceased person from recordings, photographs and messages has moved from a research curiosity to a commercial service. The practice is most prevalent in China, where it is sold in tiers: a basic avatar can be generated from a short sample of audio and video for 199 yuan (about US$30), while more detailed and interactive replications of appearance, voice and manner cost thousands of dollars. Cemetery and funeral-services operators have begun to offer them alongside traditional services.132
Because death is frequently unanticipated, the deceased will rarely have turned their mind to whether their likeness and communications may be used in this way. That raises a consent problem that existing law is not well suited to resolve: the subject cannot consent, and in most cases has no surviving legal interest on which an objection could be founded.
Control over a deceased person’s image
Australian law provides no general right to control the use of a person’s image, and privacy rights do not ordinarily survive death. Claims have historically been framed indirectly — in defamation, where the use of an image damages reputation,133 or under the misleading or deceptive conduct provisions of the Australian Consumer Law, where an image falsely suggests an endorsement.134 Neither is available to the estate of a deceased person in the ordinary case: a deceased person cannot be defamed, and the consumer law claim belongs to the trader or consumer misled rather than to the person depicted.
The statutory tort for serious invasions of privacy, discussed at A statutory right to privacy above, does not alter this. The tort is available to individuals, and the cause of action does not survive for the benefit of a deceased person’s estate.
Digital Products and Consumer Rights
Editor’s note: This section needs revision to terminology – ‘digital product’ is not a defined term. These ‘products’ and the licences to use them or the platforms in which they are available may be treated as goods or services, and the distinction sometimes matters.
What is a Digital Product?
The term digital product encompasses any item on the internet that can only be accessed via a technological device, that the user has ‘earned’ the right to use through a transaction, usually financial. Examples include e-books, video game files and movie downloads. Consumers may assume that purchasing an e-book on a website affords the same rights as purchasing a physical book on a website, but this is not always the case.
Terms and Conditions
When purchasing digital products, the rights of the consumer are dictated by the terms and conditions of the platform selling the product. As these transactions are typically concluded by browse-wrap or click-wrap methods, it is difficult to contest problems that may arise as there is no option to negotiate the terms and conditions. Australian courts have confirmed that it is the responsibility of the signatory to be aware of a website’s terms and conditions when making an online purchase.
Example: Microsoft Store’s Book Category Closure
In April 2019, Microsoft closed the book category of its online store. As well as preventing future sales, this closure affected previous sales. From July 2019, purchased e-books were permanently removed from consumer’s devices. The decision sparked conversation about what ownership means in the context of digital products, and how much control consumers have over the products they have purchased. In the instance of Microsoft Store consumers, they were licensees whose rights of use were dictated by Microsoft. Unlike purchasing a novel from a physical or online bookstore, where the purchaser can use that book regardless of what happens to the vendor where it’s purchased, e-books are controlled by the vendor and can be removed from devices or even altered after being purchased. This is despite the fact that e-book transactions are completed with ‘buy now’ options, not ‘lease now’ options.
Consumer Law and Digital Products
The Australian Consumer Law does not impose any obligations of sustained access to a purchased digital product.
The notion that users are licensing these digital products, rather than purchasing them, requires the definitions of goods and services to be considered. Consumer guarantees for goods are concerned with the quality and freedom of use of the good, whereas consumer guarantees for services are concerned with the duration and purpose of the service. It is only if digital products are considered a good that there will be a consumer right to continued use of the digital product.
The Australian Consumer Law states that the term ‘goods’ is inclusive of objects including computer software. The programs that facilitate the use of e-books, like Amazon’s Kindle app and device, and Apple’s Books app, are computer software; however, digital products do not fit into this definition as easily. In Valve Corporation v Australian Competition and Consumer Commission [2017] FCAFC 224, the Federal Court considered the implication of ‘computer software’ in relation to goods. Edelman J at [156] stated that the data that accompanies computer software is not a good, but conceded that it is difficult to differentiate the two. A recent dispute involving video games confirms that digital products are considered a service rather than a good.
Example: Ubisoft’s The Crew
In December 2023, Ubisoft, a video game publisher, removed one of its titles, The Crew, from both digital stores and the consoles of users who had already purchased the game. Ubisoft were discontinuing the servers that The Crew relied on to be played. The withdrawal of the game was permitted under the end-user license agreement. This led to a petition demanding the enactment of legislation that requires digital products to remain operational without support from its publisher. In response, the Assistant Treasurer and Minister for Financial Services stated that digital products confer a license to use the product, not a right of ownership.
As long as digital products are considered services rather than goods, the Australian Consumer Law offers limited protection for consumers of digital products. Their license to use the digital product will be governed by the terms and conditions set by the company.
-
Privacy and Other Legislation Amendment Act 2024 (Cth) sch 2 https://www.legislation.gov.au/C2024A00128, inserting Privacy Act 1988 (Cth) sch 2. Schedule 2 commenced on 10 June 2025. ↩
-
Victoria Park Racing and Recreation Grounds Co Ltd v Taylor (1937) 58 CLR 479. ↩
-
Australian Broadcasting Corporation v Lenah Game Meats Pty Ltd (2001) 208 CLR 199, [107] (Gummow and Hayne JJ), [320] (Callinan J). ↩
-
Des A Butler, ‘A Tort of Invasion of Privacy in Australia?’ (2005) 29(2) Melbourne University Law Review 339, 340. ↩
-
Australian Law Reform Commission, For Your Information: Australian Privacy Law and Practice (Report No 108, 2008) vol 1, 25–26. ↩
-
Ibid 112–13. ↩
-
Australian Competition and Consumer Commission, Digital Platforms Inquiry — Final Report (Report, June 2019) rec 19, 459 https://www.accc.gov.au/publications/digital-platforms-inquiry-final-report. ↩
-
Attorney-General’s Department, Privacy Act Review Report (Report, February 2023) 12–13 https://www.ag.gov.au/rights-and-protections/publications/privacy-act-review-report. ↩
-
Grosse v Purvis [2003] QDC 151; Doe v Australian Broadcasting Corporation [2007] VCC 281. ↩
-
Smethurst v Commissioner of Police [2020] HCA 14. ↩
-
Privacy and Other Legislation Amendment Bill 2024 (Cth); Commonwealth, Parliamentary Debates, House of Representatives, 12 September 2024 (Mark Dreyfus, Attorney-General). ↩
-
Privacy Act 1988 (Cth) sch 2 pt 1. ↩
-
Australian Broadcasting Corporation v Lenah Game Meats Pty Ltd (2001) 208 CLR 199, [126] (Gummow and Hayne JJ). ↩
-
Privacy Act 1988 (Cth) sch 2 cl 7(1). ↩
-
Privacy Act 1988 (Cth) sch 2 pt 2. The absence of a damage requirement reflects the ALRC’s recommendation that not requiring proof of actual damage would provide protection and vindication for victims and enhance the tort’s deterrent effect: Australian Law Reform Commission, Serious Invasions of Privacy in the Digital Era (Report No 123, 2014). ↩
-
Australian Law Reform Commission, Serious Invasions of Privacy in the Digital Era (Report No 123, 2014) [9.4]. ↩
-
Ibid rec 9–1, 144. ↩
-
Privacy Act 1988 (Cth) sch 2 cl 8. ↩
-
Privacy Act 1988 (Cth) sch 2 pt 3 (cll 15–18). ↩
-
Privacy Act 1988 (Cth) sch 2 cl 15. ↩
-
Privacy Act 1988 (Cth) sch 2 cl 18. ↩
-
Privacy Act 1988 (Cth) sch 2 cl 14. ↩
-
Privacy Act 1988 (Cth) sch 2 cll 11(1), 12(1). ↩
-
Ibid cl 11(3). ↩
-
Ibid cll 11(2), 11(4). ↩
-
Ibid cl 11(5). ↩
-
Ibid cl 11(6). ↩
-
Privacy Commissioner v Telstra Corporation Ltd [2017] FCAFC 4. ↩
-
Office of the Australian Information Commissioner. (2019). Chapter 13: APP 13 Correction of personal information. Australian Government. Available at: https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-13-app-13-correction-of-personal-information. ↩
-
Normann Witzleb and Julian Wagner. (2018). When is Personal Data ‘About’ or ‘Relating To’ an Individual? A Comparison of Australian, Canadian and EU Data Protection and Privacy Laws. Monash University Faculty of Law Legal Studies Research Paper No. 3189376, Available at: https://ssrn.com/abstract=3189376 or http://dx.doi.org/10.2139/ssrn.3189376. ↩
-
Parliament of Australia. (2012-13). Privacy Amendment (Enhancing Privacy Protection) Bill 2012. Available at: https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/bd/bd1213a/13bd020#_Toc340068484. ↩
-
Australian Signals Directorate, Annual Cyber Threat Report 2024–25 (Report, 14 October 2025) https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025; Australian Signals Directorate, Annual Cyber Threat Report 2023–24 (Report, 2024); Australian Signals Directorate, Annual Cyber Threat Report 2022–23 (Report, 2023). ↩
-
Information and Privacy Commission NSW, Mandatory Notification of Data Breach Scheme Trends Report: November 2023 to June 2024 (Report, October 2024) https://www.ipc.nsw.gov.au/sites/default/files/2025-01/MNDB_Scheme_Trends_Report_Nov23-Jun24.pdf. ↩
-
Office of the Australian Information Commissioner, Notifiable Data Breaches Report: July to December 2023 (Report, 2024) https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-july-to-december-2023. ↩
-
Office of the Australian Information Commissioner, Notifiable Data Breaches Report: July to December 2024 (Report, 2025) https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-july-to-december-2024. ↩
-
Office of the Australian Information Commissioner, ‘Data Breach Notifications Increase to All-Time High in 2025, New NDB Stats Show’ (Media Release, 6 July 2026) https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show. ↩
-
Latitude Financial Services, ‘Cybercrime Update’ (Media Release, 27 March 2023) https://www.latitudefinancial.com.au/about-us/media-releases/cybercrime-update-27-03-2023.html. ↩
-
Cyber Security Act 2024 (Cth) s 2 (commencement table); Cyber Security (Security Standards for Smart Devices) Rules 2025 (Cth) https://www.legislation.gov.au/F2025L00276; Cyber Security (Ransomware Payment Reporting) Rules 2025 (Cth) https://www.legislation.gov.au/F2025L00278; Department of Home Affairs, ‘Cyber Security Act’ (Web Page) https://www.homeaffairs.gov.au/cyber-security-subsite/Pages/cyber-security-act.aspx. ↩
-
Privacy and Other Legislation Amendment Act 2024 (Cth) s 2 item 8, sch 2 (inserting Privacy Act 1988 (Cth) sch 2) https://www.legislation.gov.au/C2024A00128; Office of the Australian Information Commissioner, ‘Statutory Tort for Serious Invasions of Privacy’ (Web Page) https://www.oaic.gov.au/privacy/your-privacy-rights/more-privacy-rights/statutory-tort-for-serious-invasions-of-privacy. ↩
-
James Patto and Annie Zhang, ‘2023 Government Response to the Privacy Act Review Report’ (2023) PWC Australia. ↩
-
Privacy and Other Legislation Amendment Act 2024 (Cth) https://www.legislation.gov.au/C2024A00128. ↩
-
Ibid schs 1–3. ↩
-
Explanatory Memorandum, Privacy and Other Legislation Amendment Bill 2024 (Cth). ↩
-
eSafety Commissioner, Doxing Trends and Challenges: Position Statement (Position Statement, January 2022) https://www.esafety.gov.au/sites/default/files/2022-01/Doxing-Position-Statement%20_v2.pdf. ↩
-
Office of the Australian Information Commissioner and Office of the Privacy Commissioner of Canada, Joint Investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner and Acting Australian Information Commissioner (Report, 24 August 2016) [2] https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/ashley-madison-joint-investigation. ↩
-
Criminal Code Act 1995 (Cth) s 474.17. ↩
-
Criminal Code Act 1995 (Cth) div 372 (identity crime offences, including dealing in identification information). Equivalent State offences exist — for example, Crimes Act 1900 (NSW) s 192J (dealing with identification information). ↩
-
Crimes (Domestic and Personal Violence) Act 2007 (NSW) s 13. ↩
-
Criminal Code Act 1995 (Cth) ss 474.17C, 474.17D, inserted by Privacy and Other Legislation Amendment Act 2024 (Cth) sch 3. ↩
-
Criminal Code Act 1995 (Cth) ss 474.17C(1), 474.17D(1). ↩
-
Criminal Code Act 1995 (Cth) s 474.17D. ↩
-
Criminal Code Act 1995 (Cth) ss 474.17C(2), 474.17D(2); cf Privacy Act 1988 (Cth) s 6(1) (definition of ‘personal information’). ↩
-
Privacy and Other Legislation Amendment Act 2024 (Cth) s 4. ↩
-
Office of the Australian Information Commissioner, ‘Biometric Scanning’ (Web Page) https://www.oaic.gov.au/privacy/your-privacy-rights/surveillance-and-monitoring/biometric-scanning. ↩
-
Privacy Act 1988 (Cth) s 6 (definition of ‘sensitive information’). ↩
-
National Cyber Security Centre (UK), ‘Using Biometrics’ (Web Page) https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/using-biometrics. ↩
-
Office of the Victorian Information Commissioner, ‘Biometrics and Privacy — Issues and Challenges’ (Web Page) https://ovic.vic.gov.au/privacy/resources-for-organisations/biometrics-and-privacy-issues-and-challenges/. ↩
-
ANZ, ‘Voice ID in the ANZ App’ (Web Page) https://www.anz.com.au/security/how-we-protect-you/voice-id/. ↩
-
Australian Taxation Office, ‘Voice Authentication’ (Web Page) https://www.ato.gov.au/online-services/voice-authentication. ↩
-
Privacy Act 1988 (Cth) ss 13G, 13H, 13K. ↩
-
Office of the Australian Information Commissioner, ‘Bunnings Breached Australians’ Privacy with Facial Recognition Tool’ (Media Release, 19 November 2024) https://www.oaic.gov.au/news/media-centre/bunnings-breached-australians-privacy-with-facial-recognition-tool. ↩
-
Office of the Australian Information Commissioner, ‘OAIC Statement on Administrative Review Tribunal’s Bunnings Decision’ (Statement, 4 February 2026) https://www.oaic.gov.au/news/media-centre/oaic-statement-on-administrative-review-tribunals-bunnings-decision; Office of the Australian Information Commissioner, ‘Privacy Commissioner Statement on Administrative Review Tribunal’s Bunnings Decision’ (Statement, 5 March 2026) https://www.oaic.gov.au/news/media-centre/privacy-commissioner-statement-on-administrative-review-tribunals-bunnings-decision. ↩
-
Dan Mangan, ‘Meta Agrees to $1.4 Billion Settlement in Texas Biometric Data Lawsuit over Facebook Images’, CNBC (online, 30 July 2024) https://www.cnbc.com/2024/07/30/meta-agrees-to-1point4-billion-settlement-in-texas-biometric-data-lawsuit.html; Alex Hern, ‘Facebook Pays $550m Settlement for Breaking Illinois Data Protection Law’, The Guardian (online, 31 January 2020) https://www.theguardian.com/technology/2020/jan/30/facebook-pays-550m-settlement-for-breaking-illinois-data-protection-law. ↩
-
Privacy Act 1988 (Cth) ss 6C, 6D. ↩
-
Privacy Act 1988 (Cth) sch 2; cf ss 6C, 6D. ↩
-
Telecommunications (Interception and Access) Act 1979 (Cth) ss 110A, 178, 180; Department of Home Affairs, Telecommunications (Interception and Access) Act 1979 and Part 15 of the Telecommunications Act 1997: Annual Report 2024–25 (Report, 2025) https://www.homeaffairs.gov.au/criminal-justice/files/telecommunications-interception-and-access-reports/telecommunications-interception-access-act-1979-annual-report-24-25.pdf. ↩
-
Human Rights Law Centre, Digital Rights Watch and Access Now, ‘Sweeping Metadata Laws Must Be Scaled Back’ (Media Release, 19 July 2019) https://digitalrightswatch.org.au/2019/07/19/sweeping-metadata-laws-must-be-scaled-back/. ↩
-
Parliamentary Joint Committee on Intelligence and Security, Review of the Mandatory Data Retention Regime Prescribed by Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (Report, October 2020) https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Intelligence_and_Security/Completed_Inquiries_46th_Parliament/Dataretentionregime. ↩
-
Law Council of Australia, Submission to the Parliamentary Joint Committee on Intelligence and Security, Review of the Mandatory Data Retention Regime (2019) https://lawcouncil.au/resources/submissions/review-of-the-mandatory-data-retention-regime. ↩
-
Digital Rights Ireland Ltd v Minister for Communications, Marine and Natural Resources (Court of Justice of the European Union, C-293/12 and C-594/12, ECLI:EU:C:2014:238, 8 April 2014). ↩
-
Tele2 Sverige AB v Post- och telestyrelsen (Court of Justice of the European Union, C-203/15 and C-698/15, ECLI:EU:C:2016:970, 21 December 2016). ↩
-
https://www.edps.europa.eu/data-protection/data-protection/glossary/p_en#pets European Commission, 2023. Glossary of the European Data Protection Supervisor. ↩
-
Australian Signals Directorate, Defending against the Malicious Use of the Tor Network (Advisory, 2020). ↩
-
Shelby Davis and Bruce Arrigo, ‘The Dark Web and Anonymising Technologies: Legal Pitfalls, Ethical Prospects, and Policy Directions from Radical Criminology’ (2021) 76(4) Crime, Law and Social Change 367. ↩
-
Daniel Moore and Thomas Rid, ‘Cryptopolitik and the Darknet’ (2016) 58(1) Survival 7, 15. ↩
-
Privacy Act 1988 (Cth) sch 1 (APP 2). ↩
-
Privacy Act 1988 (Cth) sch 1 (APP 11.2). ↩
-
Telecommunications (Interception and Access) Act 1979 (Cth) pt 5-1A, s 187C (two-year retention period). See Data Retention above. ↩
-
Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth), inserting Telecommunications Act 1997 (Cth) pt 15. ↩
-
Davis and Arrigo (above) 378. ↩
-
Adam Ghazi-Tehrani, ‘Mapping Real-World Use of the Onion Router’ (2023) 39(2) Journal of Contemporary Criminal Justice 239 https://doi.org/10.1177/10439862231157553. ↩
-
Moore and Rid (above) 17. ↩
-
Monia Milutinović, ‘Cryptocurrency’ (2018) 64(1) Ekonomika 105, 106. ↩
-
Ibid 106–10. ↩
-
Sean Foley, Jonathan R Karlsen and Tālis J Putniņš, ‘Sex, Drugs, and Bitcoin: How Much Illegal Activity Is Financed through Cryptocurrencies?’ (2019) 32(5) Review of Financial Studies 1798, 1799. ↩
-
Ibid 1800. ↩
-
United States Attorney’s Office, Southern District of New York, ‘Ross Ulbricht, the Creator and Owner of the “Silk Road” Website, Found Guilty in Manhattan Federal Court on All Counts’ (Press Release, 5 February 2015) https://www.justice.gov/usao-sdny/pr/ross-ulbricht-creator-and-owner-silk-road-website-found-guilty-manhattan-federal-court; United States Attorney’s Office, Southern District of New York, ‘Ross Ulbricht, a/k/a “Dread Pirate Roberts”, Sentenced in Manhattan Federal Court to Life in Prison’ (Press Release, 29 May 2015) https://www.justice.gov/usao-sdny/pr/ross-ulbricht-aka-dread-pirate-roberts-sentenced-manhattan-federal-court-life-prison. The website was seized by federal law enforcement agents in September–October 2013 in an investigation led by the Federal Bureau of Investigation, with the Drug Enforcement Administration and Internal Revenue Service Criminal Investigation: United States Attorney’s Office, Southern District of New York, ‘Manhattan US Attorney Announces Seizure of Additional $28 Million Worth of Bitcoins Belonging to Ross William Ulbricht’ (Press Release, 25 October 2013) https://www.justice.gov/archive/usao/nys/pressreleases/October13/SilkRoadSeizurePR.php. ↩
-
Executive Grant of Clemency (Full and Unconditional Pardon) for Ross William Ulbricht (US, 21 January 2025) https://www.justice.gov/pardon/media/1386096/dl?inline; United States Department of Justice, Office of the Pardon Attorney, Clemency Grants by President Donald J Trump (2025–Present) (Web Page) https://www.justice.gov/pardon/clemency-grants-president-donald-j-trump-2025-present. ↩
-
Susan Athey et al, ‘Bitcoin Pricing, Adoption, and Usage: Theory and Evidence’ (Research Paper No 16-42, Stanford University Graduate School of Business, 2016) 4. ↩
-
Foley, Karlsen and Putniņš (above) 1801. ↩
-
Katherine Sainty and Belyndy Rowe, ‘OAIC v Facebook’ (2020) 39(2) Communications Law Bulletin 17. ↩
-
See also, My Health Records (Information Commissioner Enforcement Powers) Guidelines 2016 (Cth). ↩
-
See, Auditor-General Report No.13 2019–20 Implementation of the My Health Record System at 17-18 ↩
-
Loi n° 2020-1266 du 19 octobre 2020 visant à encadrer l’exploitation commerciale de l’image d’enfants de moins de seize ans sur les plateformes en ligne [Law No 2020-1266 of 19 October 2020 on regulating the commercial exploitation of the image of children under sixteen on online platforms] (France). ↩
-
Online Safety Act 2021 (Cth) pt 5 (‘Cyber-bullying material targeted at an Australian child’) ss 65–67. This is the child-specific removal notice scheme. The separate scheme in pt 9 div 2 (‘Removal notices relating to class 1 material’) ss 109–111 is not child-specific; it is the power considered in eSafety Commissioner v X Corp, discussed below. ↩
-
Online Safety (Basic Online Safety Expectations) Determination 2022 (Cth). ↩
-
eSafety Commissioner v X Corp [2024] FCA 499. The case is discussed in detail in the Content Regulation and Online Classification chapter. ↩
-
Online Safety Act 2023 (UK) pt 10. ↩
-
Privacy and Other Legislation Amendment Act 2024 (Cth) sch 1, inserting Privacy Act 1988 (Cth) s 26GC. ↩
-
Privacy Act 1988 (Cth) s 26GC(10). ↩
-
Office of the Australian Information Commissioner, OAIC Children’s Online Privacy Code (Issues Paper, 12 June 2025) 6. ↩
-
Privacy Act 1988 (Cth) ss 26C, 26GC(3). ↩
-
Office of the Australian Information Commissioner, OAIC Children’s Online Privacy Code (Issues Paper, 12 June 2025) 3. ↩
-
Rebecca Brown, ‘Better Privacy Protections for Children Are Coming’, Office of the Australian Information Commissioner (Blog Post, 17 September 2024) https://www.oaic.gov.au/news/blog/better-privacy-protections-for-children-are-coming. ↩
-
Information Commissioner’s Office (UK), Age Appropriate Design: A Code of Practice for Online Services (Code of Practice) https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/. ↩
-
California Age-Appropriate Design Code Act, AB 2273 (2022). On the injunction, see NetChoice LLC v Bonta, No 25-2366 (9th Cir, 12 March 2026), affirming the district court’s preliminary injunction ‘insofar as it enjoined enforcement of California Civil Code §§ 1798.99.31(b)(1)–(4) and 1798.99.31(b)(7)’. ↩
-
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (General Data Protection Regulation) [2016] OJ L 119/1, art 17 https://gdpr-info.eu/art-17-gdpr/. ↩
-
General Data Protection Regulation art 3 https://gdpr-info.eu/art-3-gdpr/. See also Recitals 22–24. ↩
-
Francisco Silva, ‘The Right to Be Forgotten’, Law Society Journal (online, 1 December 2023) https://lsj.com.au/articles/the-right-to-be-forgotten/. The underlying figure comes from a survey conducted by the professional services firm Deloitte and reported in journalism; it is vendor-generated data rather than an independent study, and should be treated with caution. On the data protection officer role itself, see General Data Protection Regulation arts 37–39. ↩
-
Spam Act 2003 (Cth) ss 24–25; Crimes Act 1914 (Cth) s 4AA; Crimes (Amount of a Penalty Unit) Instrument 2026 (Cth) https://www.legislation.gov.au/F2026N00424. The penalty unit is $364 for contraventions committed on or after 1 July 2026, and was $330 for contraventions committed between 7 November 2024 and 30 June 2026: Australian Securities and Investments Commission, ‘Fines and Penalties’ (Web Page, 1 July 2026) https://www.asic.gov.au/about-asic/asic-investigations-and-enforcement/fines-and-penalties. ↩
-
Do Not Call Register Act 2006 (Cth). ↩
-
The Australia Institute, Go Away, Please (Discussion Paper No 104, December 2008). The figures are reported as survey findings by the Institute and have not been independently verified here. ↩
-
Do Not Call Register Act 2006 (Cth) ss 13, 14. ↩
-
Do Not Call Register Act 2006 (Cth) ss 11(1), 12B(1). ↩
-
Do Not Call Register Act 2006 (Cth) ss 5, 5B. ↩
-
Do Not Call Register Act 2006 (Cth) ss 11(2), 12B(2). ↩
-
Do Not Call Register Act 2006 (Cth) sch 2 cl 2. ↩
-
Do Not Call Register Act 2006 (Cth) sch 2 cll 3, 4. ↩
-
Do Not Call Register Act 2006 (Cth) sch 1 cll 2–4. Designated marketing faxes are dealt with separately, in sch 1A. ↩
-
Do Not Call Register Act 2006 (Cth) pt 4. ↩
-
Do Not Call Register Act 2006 (Cth) s 40, sch 3. ↩
-
Do Not Call Register Act 2006 (Cth) s 3 (note); Telecommunications Act 1997 (Cth) pts 26, 27, 31A. ↩
-
Do Not Call Register, ‘Compliance and Breaches’ (Web Page) https://www.donotcall.gov.au/industry/industry-overview/compliance-and-breaches. Penalty maxima under the Act are expressed in penalty units, the value of which is indexed under s 4AA of the Crimes Act 1914 (Cth); the dollar figures published by the regulator should be checked against the current penalty unit value. ↩
-
Do Not Call Register Regulations 2017 (Cth) s 6; Do Not Call Register Act 2006 (Cth) ss 5(7), 39(4). ↩
-
Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 (Cth) ss 3, 5. ↩
-
Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 (Cth) s 8; the express-consent exception to the permitted hours is s 8(5). ↩
-
Nidhi Thakur and Rajinder Verma, ‘Right to Privacy in India: From KS Puttaswamy to the Digital Personal Data Protection Act, 2023’ (2025) 10(6) International Journal of Novel Research and Development 770 https://www.ijnrd.org/papers/IJNRD2506287.pdf. ↩
-
eSafety Commissioner, ‘What Happens to Your Digital Accounts after You Die’ (Web Page, 1 November 2023) https://www.esafety.gov.au/key-topics/digital-wellbeing/what-happens-to-your-digital-accounts-after-you-die. ↩
-
Eric K Clemons et al, ‘A Face of One’s Own: The Role of an Online Personae in a Digital Age and the Right to Control One’s Own Online Personae in the Presence of Digital Hacking’ (2024) 34(1) Electronic Markets 31 https://doi.org/10.1007/s12525-024-00713-3. ↩
-
Amelia Acker and Jed R Brubaker, ‘Death, Memorialization, and Social Media: A Platform Perspective for Personal Archives’ (2014) 77 Archivaria 1. ↩
-
Adam Steen et al, ‘Managing Digital Assets on Death and Disability: An Examination of the Determinants of Digital Asset Planning Literacy’ (2024) 49(4) Australian Journal of Management 561. ↩
-
Kwan Y Cheng, ‘The Law of Digital Afterlife: The Chinese Experience of AI “Resurrection” and “Grief Tech”’ (2025) 33 International Journal of Law and Information Technology https://doi.org/10.1093/ijlit/eaae029; Emily Feng, ‘Chinese Companies Offer to “Resurrect” Deceased Loved Ones with AI Avatars’, NPR (online, 21 July 2024). ↩
-
Ettingshausen v Australian Consolidated Press Ltd (1991) 23 NSWLR 443. ↩
-
Talmax Pty Ltd v Telstra Corporation Ltd [1997] 2 Qd R 444. ↩